[{"data":1,"prerenderedAt":693},["ShallowReactive",2],{"uc-aiops-incident-triage":3,"uc-regulations":493},{"useCase":4,"evidence":217,"blitsAiDeployments":366,"benchmarks":367,"indicative":389,"related":392,"indexability":491,"includeUnpublished":223},{"title":5,"shortTitle":6,"seoTitle":7,"metaDescription":8,"status":9,"definition":10,"aliases":11,"industries":17,"functions":23,"patterns":27,"channels":33,"audience":36,"autonomy":37,"adoptionStage":38,"problem":39,"problemStats":40,"howItWorks":41,"valueDrivers":42,"kpis":47,"indicativeValue":52,"macroEstimates":97,"feasibility":98,"implementation":113,"risk":160,"blitsAi":191,"faq":193,"related":206,"datePublished":212,"dateModified":212,"lastVerified":212,"changelog":213,"slug":216},"AI for IT incident triage and root cause analysis (AIOps)","AIOps incident triage","AI incident triage and root cause analysis","AI groups alerts into one incident, routes it and ranks likely root causes for an engineer to confirm. Meta reports 42% top five accuracy in backtests.","published","AI that turns a flood of monitoring alerts into one probable incident, routes it to the right team, proposes likely root causes and remediation from runbooks and past incidents, and drafts the stakeholder updates and the post incident review, while an engineer authorizes every change.",[12,13,14,15,16],"AIOps","incident management copilot","SRE copilot","AI root cause analysis","alert correlation",[18,19,20,21,22],"cross-industry","banking","technology","telecommunications","payments",[24,25,26],"it-and-engineering","operations","risk-management",[28,29,30,31,32],"anomaly-detection","classification-and-routing","summarization","rag-knowledge-assistant","agentic-workflow",[34,35],"internal-tools","microsoft-teams","employee-facing","copilot","early-adopters","When a critical system degrades, the monitoring estate fires a burst of alerts across\napplications, infrastructure and dependent services. Engineers spend the first part of the\nincident working out which alerts belong together, which team owns the problem and what changed,\nwhile business and customer teams ask for updates. Mizuho and IBM described the pattern plainly:\nwhen an error is detected, operators receive an influx of messages and reports, which makes it\nhard to pinpoint the cause and delays recovery.\n\nTime to recover is not only a cost question. For regulated firms an outage of a critical service\ncan become a reportable event. DORA requires EU financial entities to detect, manage, record and\nclassify ICT related incidents, to report major ones and to review them afterwards. NIS2 sets\nincident reporting duties for essential and important entities, including telecom operators. APRA\nCPS 230 expects Australian regulated entities to keep critical operations within tolerance levels\nthrough severe disruptions and to notify APRA of tolerance breaches. The knowledge that shortens an incident\n(runbooks, past post incident reviews, recent changes) exists, but it is scattered and nobody has\ntime to search it at 3 a.m.",[],"1. **Correlate.** Alerts, logs, traces and change events are grouped into one probable incident\n   using topology and timing, so responders see one problem instead of a stream of separate alerts.\n2. **Route.** A classifier or a set of team agents decides which team owns the incident, based\n   on service ownership and past incidents, and pages them with the correlated evidence.\n3. **Suggest causes.** The AI ranks recent changes and known failure patterns as likely root\n   causes and retrieves the matching runbook steps and similar past incidents, with links so the\n   engineer can verify each suggestion.\n4. **Propose, do not execute.** Remediation is proposed as a concrete command or change; a\n   policy layer checks it, and an engineer confirms it before anything runs.\n5. **Communicate.** The AI drafts status updates for stakeholders at a set cadence from the\n   incident timeline, for the incident commander to approve.\n6. **Learn.** After recovery it drafts the post incident review from the timeline, chat and\n   changes, and proposes follow up actions and runbook updates.",[43,44,45,46],"speed","risk-reduction","employee-productivity","customer-experience",[48,49,50,51],"mttr-reduction","accuracy","detection-rate-improvement","time-saved-per-task",{"referenceOrg":53,"inputs":54,"formula":92,"currency":93,"period":94,"resultLabel":95,"caveat":96},"A bank with 120 major IT incidents a year on customer facing services",[55,61,68,75,81,87],{"key":56,"label":57,"low":58,"high":58,"unit":59,"note":60},"incidents","Major incidents per year",120,"incidents per year","The reference organization. Replace with your own count of priority 1 and 2 incidents.",{"key":62,"label":63,"low":64,"high":65,"unit":66,"note":67},"hoursToRestore","Average hours from detection to mitigation",2,4,"hours per incident","Editorial assumption. Replace with your own mean time to restore.",{"key":69,"label":70,"low":71,"high":72,"unit":73,"note":74},"reduction","Reduction in time to mitigate",0.1,0.25,"fraction of time","Conservative against the evidence on this page (Microsoft reports a 38% time to mitigate reduction for one team; TD Bank's vendor reports 20% faster response), because those are the best early results.",{"key":76,"label":77,"low":65,"high":78,"unit":79,"note":80},"responders","Engineers engaged per incident",8,"engineers","Editorial assumption including the incident commander and service owners.",{"key":82,"label":83,"low":84,"high":58,"unit":85,"note":86},"hourlyCost","Fully loaded engineer hour",80,"USD per hour","Editorial assumption. Replace with your own rate.",{"key":88,"label":89,"low":64,"high":90,"unit":66,"note":91},"reviewHoursSaved","Hours saved drafting each post incident review and status updates",5,"Editorial assumption; the review still needs the owning team's analysis.","incidents * (hoursToRestore * reduction * responders + reviewHoursSaved) * hourlyCost","USD","per year","Engineering time released during and after major incidents","Engineering time only. It leaves out the largest effect, the revenue, customer harm and regulatory exposure avoided by restoring service faster, which depends on the service and is best estimated per critical business service against its impact tolerance.",[],{"complexity":99,"complexityNote":100,"dataPrerequisites":101,"integrations":107},"medium","Summaries and drafted updates are quick wins. Correlation and root cause suggestions depend on a service map, clean change records and labeled past incidents; without them, suggestions are generic. Automated remediation is a separate, higher risk step that most firms defer.",[102,103,104,105,106],"A current service catalog with owners and dependencies","Alerts, logs and traces from the observability platform","Change records and deployment history linked to services","Past incidents and post incident reviews with the confirmed root cause","Runbooks with an owner and a review date",[108,109,110,111,112],"Observability and monitoring platforms","IT service management tool for incidents, problems and changes","Paging and on call scheduling","ChatOps in Microsoft Teams or Slack","Code repositories and deployment pipelines for change history",{"steps":114,"guardrails":133,"humanInTheLoop":140,"kpisToInstrument":141,"failureModes":147},[115,118,121,124,127,130],{"title":116,"detail":117},"Start with the write ups, not the fixes","The lowest risk value is drafting stakeholder updates and post incident reviews from the incident timeline. It earns trust with engineers and builds the labeled incident history the later steps need.",{"title":119,"detail":120},"Clean the service map and change feed","Correlation and routing are only as good as ownership data and change records. Fix the services with the most incidents first.",{"title":122,"detail":123},"Add root cause suggestions with evidence","Show a short ranked list, each item with the change, the log excerpt or the past incident that supports it. Meta narrows its suggestions to the top five code changes, measures the ranker by backtesting on historical investigations and holds back low confidence answers.",{"title":125,"detail":126},"Measure on history before going live","Replay past incidents and measure how often the true cause was in the suggestions and how often routing picked the right team. Publish the number to the engineers who will use it.",{"title":128,"detail":129},"Keep remediation behind confirmation","Let the AI propose commands, pass them through a policy layer (no global restarts at peak, two person approval for high impact changes) and require an engineer to confirm. Google's SRE tooling logs what the AI proposed and what the human approved.",{"title":131,"detail":132},"Close the loop","Feed confirmed root causes and runbook fixes from each review back into the knowledge base, so the next incident starts with better context.",[134,135,136,137,138,139],"No change to production without explicit confirmation by an authorized engineer","A policy layer that blocks or escalates high impact commands regardless of what the AI proposes","Every suggestion shows its evidence (change, log, past incident) so it can be verified in seconds","Low confidence suggestions are held back rather than shown","Full logging of AI proposals, human decisions and timestamps into the incident timeline","Secrets and customer data masked before logs reach a model","The incident commander owns the incident, decides on customer communication and approves every status update. Engineers authorize every remediation. The owning team signs off the post incident review and its actions; the AI drafts, it does not conclude.",[142,143,144,145,146],"Mean time to detect, to engage the right team and to mitigate, before and after, per service","Share of incidents where the confirmed root cause was among the AI suggestions","Routing accuracy (incidents that stayed with the first team paged)","Alerts per incident after correlation","Time from resolution to a published post incident review",[148,151,154,157],{"title":149,"detail":150},"Plausible but wrong root cause","An engineer anchors on a confident suggestion and loses time. Show evidence per suggestion, hold back low confidence ones and track the hit rate openly.",{"title":152,"detail":153},"Automation that amplifies the outage","An automated fix runs against the wrong target or at the wrong time. Keep confirmation and a policy layer in front of every mutation, and rehearse in game days.",{"title":155,"detail":156},"Stale runbooks retrieved with authority","The AI surfaces an outdated procedure. Give every runbook an owner and a review date and prefer recent post incident reviews.",{"title":158,"detail":159},"Noise moved, not removed","Correlation merges unrelated alerts or hides a second incident. Let responders split incidents easily and review correlation quality weekly.",{"euAiAct":161,"regulations":164,"guidance":171,"controls":184,"incidents":190},{"tier":162,"basis":163},"minimal","An internal tool that supports engineers on IT incidents; it is not a use listed in Annex III and makes no decisions about people. Annex III point 2 covers AI used as a safety component in the management and operation of critical digital infrastructure, and recital 55 limits safety components to systems that directly protect the physical integrity of that infrastructure or the health and safety of persons and property. A triage copilot that proposes causes and fixes to engineers does not normally do that, but operators of critical digital infrastructure (cloud, data centers, telecom networks) should confirm this for their own design.",[165,166,167,168,169,170],"dora","apra-cps-230","nist-ai-rmf","iso-42001","gdpr","nis2",[172,178],{"title":173,"issuer":174,"region":175,"url":176,"note":177},"Digital Operational Resilience Act (Regulation (EU) 2022/2554)","European Union","europe","https://eur-lex.europa.eu/eli/reg/2022/2554/oj","Financial entities must detect, manage, record and classify ICT related incidents (Articles 17 and 18), report major ones (Article 19) and review major incidents afterwards (Article 13); AI drafted timelines and reviews become part of that record.",{"title":179,"issuer":180,"region":181,"url":182,"note":183},"Operational risk management (CPS 230)","Australian Prudential Regulation Authority","asia-pacific","https://www.apra.gov.au/operational-risk-management","Regulated entities must keep critical operations within tolerance levels through severe disruptions and notify APRA of operational risk incidents likely to have a material impact and of disruptions to a critical operation outside tolerance, which is the measure AIOps value should be judged against.",[185,186,187,188,189],"Written limits on what the AI may propose and what always needs a named approver","Incident timeline that records AI suggestions, human decisions and timestamps","Backtest results per release of the model or prompts before engineers rely on it","Periodic review of suggestion hit rate and routing accuracy by the SRE or operations lead","Inventory entry for the AIOps system with an owner and a review date",[],{"howToBuild":192},"On Blits.ai this is an **agentic workflow** triggered **via API** by the incident management or\nmonitoring tool when a major incident opens. The workflow's **custom functions** (REST calls)\nfetch the correlated alerts, recent changes and service ownership, and an **AI agent** with a\n**knowledge base** of runbooks and past post incident reviews, retrieved with **hybrid retrieval**,\nproposes likely causes with links to the evidence. Any action above a set threshold goes\nthrough **human in the loop confirmation**, and the **tool execution policy** limits which tools\nthe agent may call at all.\n\nResponders talk to the agent in **Microsoft Teams** or Slack, where it drafts status updates and,\nafter recovery, the post incident review. **Run history with a full audit trail** keeps every\nsuggestion and approval for the incident record, **PII masking** at the gateway masks personal\ndata in what responders type, and **test suites** replay past incidents before each change goes\nlive. Logs and alerts fetched by custom functions do not pass the gateway, so mask secrets and\ncustomer data at the source or inside the custom function before they reach the agent. The\nplatform is model agnostic, so the operations team can choose the model per agent.",[194,197,200,203],{"question":195,"answer":196},"How accurate is AI root cause analysis today?","It helps, but it is not an oracle. Meta reports that in backtesting 42% of investigations had the root cause in the top five suggested code changes, and Microsoft reports 90% accuracy for its team triage agents in early results. Treat suggestions as a ranked shortlist with evidence, not an answer.",{"question":198,"answer":199},"Should the AI fix incidents on its own?","Not at first, and not for high impact changes. Keep the AI proposing and an engineer confirming, with a policy layer in between; Google's SRE tooling forces a confirmation step and logs what the AI proposed and what the human approved. Automate only narrow, reversible fixes after a track record.",{"question":201,"answer":202},"Where does the value show up first?","In routing and write ups. Getting the incident to the right team faster and drafting updates and post incident reviews saves time on every incident, while root cause suggestions improve as the labeled incident history grows.",{"question":204,"answer":205},"Does this matter to regulators?","Yes for financial firms. DORA in the EU sets rules for managing, recording and reporting ICT related incidents, and CPS 230 in Australia expects critical operations to stay within tolerance levels, so the AI's suggestions and the human decisions belong in the incident record.",[207,208,209,210,211],"it-service-desk-resolution-agent","network-fault-triage-copilot","developer-coding-assistant","ai-model-inventory","support-knowledge-article-generation","2026-09-27",[214],{"date":212,"note":215},"First published","aiops-incident-triage",[218,249,282,308,337],{"title":219,"useCases":220,"organization":221,"vendors":226,"summary":230,"stage":231,"year":232,"channels":233,"languages":234,"metrics":236,"outcomeDisclosed":223,"sources":237,"verification":243,"grade":246,"id":247,"organizationSlug":248},"Google: SREs use Gemini CLI from page to postmortem",[216],{"name":222,"anonymized":223,"country":224,"region":225,"industry":20},"Google",false,"US","global",[227],{"name":228,"role":229},"Google (Gemini)","in-house","Google site reliability engineers use an agent in the Gemini CLI across an outage: reading the page, investigating, proposing mitigations, finding the root cause and drafting the postmortem. Every proposed change passes a policy layer (for example rules that need two person approval) and a forced human confirmation, and every proposal and approval is logged. No outcome figures are published.","production",2026,[34],[235],"en",[],[238],{"url":239,"title":240,"publisher":241,"date":242},"https://cloud.google.com/blog/topics/developers-practitioners/how-google-sres-use-gemini-cli-to-solve-real-world-outages","How Google SREs Use Gemini CLI to Solve Real-World Outages","Google Cloud Blog","2026-01-22",{"level":244,"checkedAt":245},"source-verified","2026-09-26","B","google-sre-gemini-cli-incident-response","google",{"title":250,"useCases":251,"organization":252,"vendors":254,"summary":256,"stage":231,"year":257,"channels":258,"languages":259,"metrics":260,"outcomeDisclosed":273,"sources":274,"verification":279,"grade":246,"id":280,"organizationSlug":281},"Microsoft Azure: Triangle multi agent incident triage",[216],{"name":253,"anonymized":223,"country":224,"region":225,"industry":20},"Microsoft",[255],{"name":253,"role":229},"Azure uses the Triangle System to triage incidents with AI agents. In local triage, one agent per engineering team, built on the team's historical incidents and troubleshooting guides, accepts or rejects an incoming incident on the team's behalf and can recommend the team it should move to; a global triage layer coordinates the agents to route incidents. Local triage has been in production since mid 2024 and was live for six teams in January 2025, with more than 15 onboarding; Microsoft reports triage accuracy and a time to mitigate reduction for one team as initial results.",2025,[34],[235],[261,269],{"kpi":49,"value":262,"unit":263,"qualifier":264,"period":265,"claimant":266,"quote":267,"sourceUrl":268},90,"percent","exact","initial results, as of January 2025","organization","The initial results are promising, with agents achieving 90% accuracy and one team saw a reduction in their TTM of 38%, significantly reducing the impact to customers.","https://azure.microsoft.com/en-us/blog/optimizing-incident-management-with-aiops-using-the-triangle-system/",{"kpi":48,"value":270,"unit":263,"qualifier":264,"period":271,"baseline":272,"claimant":266,"quote":267,"sourceUrl":268},38,"one team, initial results","time to mitigate (TTM) before the agents",true,[275],{"url":268,"title":276,"publisher":277,"date":278},"Optimizing incident management with AIOps using the Triangle System","Microsoft Azure Blog","2025-03-06",{"level":244,"checkedAt":245},"microsoft-azure-triangle-incident-triage",null,{"title":283,"useCases":284,"organization":285,"vendors":287,"summary":290,"stage":231,"year":291,"channels":292,"languages":293,"metrics":294,"outcomeDisclosed":273,"sources":301,"verification":306,"grade":246,"id":307,"organizationSlug":281},"Meta: AI assisted root cause analysis for reliability investigations",[216],{"name":286,"anonymized":223,"country":224,"region":225,"industry":20},"Meta",[288],{"name":289,"role":229},"Meta (Llama)","Meta's reliability investigation tooling uses a heuristic retriever (code ownership, the runtime code graph of impacted systems) to narrow thousands of recent code changes to a few hundred, then a fine tuned Llama 2 model ranks them to the five most likely root causes when an investigation is opened. Meta reports the result from backtesting on historical investigations in its web monorepo and stresses that responders must be able to verify the suggestions.",2024,[34],[235],[295],{"kpi":49,"value":296,"unit":263,"qualifier":264,"period":297,"baseline":298,"claimant":266,"quote":299,"sourceUrl":300},42,"backtesting on historical investigations, web monorepo","root cause among the top five suggested code changes","Based on exhaustive backtesting, with historical investigations and the information available at their start, 42% of these investigations had the root cause in the top five suggested code changes.","https://engineering.fb.com/2024/06/24/data-infrastructure/leveraging-ai-for-efficient-incident-response/",[302],{"url":300,"title":303,"publisher":304,"date":305},"Leveraging AI for efficient incident response","Engineering at Meta","2024-06-24",{"level":244,"checkedAt":245},"meta-ai-assisted-root-cause-analysis",{"title":309,"useCases":310,"organization":311,"vendors":314,"summary":318,"stage":319,"year":291,"channels":320,"languages":321,"metrics":322,"outcomeDisclosed":273,"sources":329,"verification":334,"grade":335,"id":336,"organizationSlug":281},"Mizuho: generative AI for event detection and recovery in IT operations (proof of concept)",[216],{"name":312,"anonymized":223,"country":313,"region":181,"industry":19},"Mizuho Financial Group","JP",[315],{"name":316,"role":317},"IBM","platform","Mizuho and IBM ran a three month proof of concept that added patterns likely to cause errors in incident response to generative AI on IBM watsonx and linked it to the application that supports event detection, so that operators flooded with messages during a disruption can find the cause faster. Accuracy was measured on actual data. Both firms said they planned to expand the proof of concept and apply it to production, and to use generative AI for incident management and failure analysis next.","pilot",[34],[],[323],{"kpi":49,"value":324,"unit":263,"qualifier":264,"period":325,"claimant":326,"quote":327,"sourceUrl":328},98,"three month trial","vendor","The new solution demonstrated a 98% accuracy[1] in monitoring and responding to error messages during a three-month trial.","https://newsroom.ibm.com/2024-05-22-Mizuho-and-IBM-Unveil-Generative-AI-Initiative-to-Accelerate-Recovery-Time-in-Operations",[330],{"url":328,"title":331,"publisher":332,"date":333},"Mizuho and IBM Unveil Generative AI Initiative to Accelerate Recovery Time in Operations","IBM Newsroom","2024-05-22",{"level":244,"checkedAt":245},"C","mizuho-generative-ai-event-detection",{"title":338,"useCases":339,"organization":340,"vendors":344,"summary":347,"stage":231,"year":291,"channels":348,"languages":349,"metrics":350,"outcomeDisclosed":273,"sources":359,"verification":364,"grade":335,"id":365,"organizationSlug":281},"TD Bank: AI powered observability for proactive incident detection",[216],{"name":341,"anonymized":223,"country":342,"region":343,"industry":19},"TD Bank","CA","north-america",[345],{"name":346,"role":317},"Dynatrace","TD Bank is consolidating roughly ten monitoring tools across its clouds into one observability platform whose AI identifies the root cause of emerging issues across its hybrid, multicloud estate, so teams can respond to transaction failures before users are affected. The customer story does not describe the AI as generative, and the outcome figures come from the vendor.",[34],[235],[351,356],{"kpi":50,"value":352,"unit":263,"qualifier":264,"baseline":353,"claimant":326,"quote":354,"sourceUrl":355},25,"incidents identified proactively, before the platform","As a result, TD Bank is identifying 25% more incidents proactively and responding to them 20% faster.","https://www.dynatrace.com/customers/td-bank/",{"kpi":48,"value":357,"unit":263,"qualifier":264,"baseline":358,"claimant":326,"quote":354,"sourceUrl":355},20,"time to respond to and resolve IT incidents before the platform, vendor phrasing \"responding to them 20% faster\"",[360],{"url":355,"title":361,"publisher":346,"date":362,"archivedUrl":363},"TD Bank customer story","2024-04-29","https://web.archive.org/web/20240523164055/https://www.dynatrace.com/customers/td-bank/",{"level":244,"checkedAt":212},"td-bank-aiops-observability",1,[368,377,384],{"kpi":49,"label":369,"unit":263,"aggregate":273,"higherIsBetter":273,"n":370,"nUpTo":371,"median":262,"min":296,"max":324,"byClaimant":372,"vendorOnly":223,"points":373},"Accuracy",3,0,{"organization":64,"vendor":366,"regulator":371,"independent":371},[374,375,376],{"evidenceId":336,"organization":312,"value":324,"qualifier":264,"claimant":326,"grade":335,"pooled":273},{"evidenceId":280,"organization":253,"value":262,"qualifier":264,"claimant":266,"grade":246,"pooled":273},{"evidenceId":307,"organization":286,"value":296,"qualifier":264,"claimant":266,"grade":246,"pooled":273},{"kpi":48,"label":378,"unit":263,"aggregate":273,"higherIsBetter":273,"n":64,"nUpTo":371,"median":379,"min":357,"max":270,"byClaimant":380,"vendorOnly":223,"points":381},"Time to repair reduction",29,{"organization":366,"vendor":366,"regulator":371,"independent":371},[382,383],{"evidenceId":280,"organization":253,"value":270,"qualifier":264,"claimant":266,"grade":246,"pooled":273},{"evidenceId":365,"organization":341,"value":357,"qualifier":264,"claimant":326,"grade":335,"pooled":273},{"kpi":50,"label":385,"unit":263,"aggregate":273,"higherIsBetter":273,"n":366,"nUpTo":371,"median":352,"min":352,"max":352,"byClaimant":386,"vendorOnly":273,"points":387},"Detection improvement",{"organization":371,"vendor":366,"regulator":371,"independent":371},[388],{"evidenceId":365,"organization":341,"value":352,"qualifier":264,"claimant":326,"grade":335,"pooled":273},{"low":390,"high":391},26880,187200,[393,417,438,457,474],{"slug":207,"title":394,"shortTitle":395,"definition":396,"status":9,"industries":397,"functions":400,"patterns":401,"audience":36,"autonomy":403,"adoptionStage":404,"evidenceCount":78,"publicEvidenceCount":405,"organizations":406,"bestGrade":246,"headline":412,"lastVerified":212,"indexable":273},"AI agent for IT service desk resolution","IT service desk resolution","An AI agent in Microsoft Teams, Slack or the intranet that takes the high volume IT support queue, such as password and MFA resets, account unlocks, VPN, device and software requests, and resolves common requests by acting in the identity and IT service management systems, handing the rest to the right resolver group with the context attached.",[18,19,20,398,399],"retail-and-ecommerce","healthcare",[24,25],[402,32,31,29],"conversational-agent","supervised-agent","mainstream",6,[407,408,409,316,410,411],"7-Eleven Vietnam","Bank of America","Equinix","Mercari US","Vituity",{"kpi":413,"label":414,"unit":263,"n":64,"nUpTo":371,"kind":415,"value":416,"qualifier":264,"claimant":326,"organization":410,"vendorReported":273},"employee-adoption","Employee adoption","reported",94,{"slug":208,"title":418,"shortTitle":419,"definition":420,"status":9,"industries":421,"functions":422,"patterns":424,"audience":36,"autonomy":37,"adoptionStage":38,"segment":425,"evidenceCount":405,"publicEvidenceCount":405,"organizations":426,"bestGrade":246,"headline":433,"lastVerified":212,"indexable":273},"AI copilot for network operations centre fault triage","NOC fault triage copilot","AI in the network operations centre (NOC) that correlates alarms and performance data from radio, transport, core and fixed networks into a small number of probable faults, ranks them by customer impact, proposes the likely root cause and fix from runbooks, vendor documentation and past tickets, and routes the ticket to the right team, while an engineer decides what to change.",[21],[423,25],"network-operations",[28,29,31,30,32],"network",[427,428,429,430,431,432],"Bell Canada","Deutsche Telekom","KDDI","Orange","Telstra","Vodafone",{"kpi":434,"label":435,"unit":263,"n":366,"nUpTo":371,"kind":415,"value":436,"qualifier":437,"claimant":266,"organization":428,"vendorReported":223},"processing-time-reduction","Cycle time reduction",95,"at-least",{"slug":209,"title":439,"shortTitle":440,"definition":441,"status":9,"industries":442,"functions":445,"patterns":446,"audience":36,"autonomy":37,"adoptionStage":404,"evidenceCount":405,"publicEvidenceCount":405,"organizations":448,"bestGrade":246,"headline":453,"lastVerified":212,"indexable":273},"AI coding assistant for software developers","Developer coding assistant","An AI assistant in the developer's IDE and code review flow that completes and generates code, explains unfamiliar modules, drafts unit tests and reviews pull requests for common defects, while generated code goes through the same review, testing and change controls as any other code.",[18,19,443,20,444],"capital-markets","professional-services",[24],[447],"code-generation",[449,450,408,451,452,286],"Accenture","ANZ","Citi","CME Group",{"kpi":454,"label":455,"unit":263,"n":370,"nUpTo":371,"kind":456,"value":357,"qualifier":264,"claimant":281,"organization":281,"vendorReported":223},"productivity-gain","Productivity gain","median",{"slug":210,"title":458,"shortTitle":459,"definition":460,"status":9,"industries":461,"functions":465,"patterns":467,"audience":36,"autonomy":37,"adoptionStage":38,"evidenceCount":65,"publicEvidenceCount":65,"organizations":469,"bestGrade":246,"headline":281,"lastVerified":212,"indexable":273},"AI system and model inventory with shadow AI discovery","AI model inventory","A governed register of every AI system and model an organization builds, buys or uses, with its owner, purpose, data, risk tier and approval status, kept current by AI that discovers unregistered use, reads the documentation and assembles the evidence a board, auditor or supervisor asks for.",[18,19,462,463,464],"insurance","government","manufacturing",[26,466,24],"regulatory-compliance",[32,468,31,29],"document-processing",[470,471,472,473],"Board of Governors of the Federal Reserve System","Office of Management and Budget","Unilever","U.S. Department of Justice",{"slug":211,"title":475,"shortTitle":476,"definition":477,"status":9,"industries":478,"functions":480,"patterns":483,"audience":36,"autonomy":37,"adoptionStage":485,"evidenceCount":65,"publicEvidenceCount":65,"organizations":486,"bestGrade":246,"headline":281,"lastVerified":212,"indexable":273},"AI for support knowledge article generation and maintenance","Knowledge article generation","AI that drafts knowledge base articles from resolved tickets, cases and conversations, detects questions the knowledge base does not answer and articles that are outdated or contradict each other, and proposes new or revised articles for a knowledge owner to review and publish.",[18,463,479],"automotive",[481,482,24],"knowledge-management","customer-service",[484,30,29],"content-generation","emerging",[487,488,489,490],"Centers for Disease Control and Prevention","Internal Revenue Service","U.S. National Science Foundation","Rivian",{"indexable":273,"reasons":492},[],[494,500,505,511,517,521,528,535,542,545,551,557,564,571,577,581,588,594,600,606,612,618,624,629,634,641,647,652,657,664,670,676,682,687],{"id":495,"label":496,"issuer":174,"region":175,"url":497,"description":498,"useCases":499,"indexable":273},"eu-ai-act","EU AI Act","https://eur-lex.europa.eu/eli/reg/2024/1689/oj","Regulation (EU) 2024/1689: risk based rules for AI systems, with obligations for high risk systems listed in Annex III and transparency duties under Article 50.",197,{"id":169,"label":501,"issuer":174,"region":175,"url":502,"description":503,"useCases":504,"indexable":273},"GDPR","https://eur-lex.europa.eu/eli/reg/2016/679/oj","General Data Protection Regulation, including Article 22 on decisions based solely on automated processing.",180,{"id":168,"label":506,"issuer":507,"region":225,"url":508,"description":509,"useCases":510,"indexable":273},"ISO/IEC 42001","ISO and IEC","https://www.iso.org/standard/81230.html","The international management system standard for AI.",110,{"id":167,"label":512,"issuer":513,"region":343,"url":514,"description":515,"useCases":516,"indexable":273},"NIST AI Risk Management Framework","NIST","https://www.nist.gov/itl/ai-risk-management-framework","Voluntary US framework to map, measure, manage and govern AI risk, with a generative AI profile.",83,{"id":165,"label":518,"issuer":174,"region":175,"url":176,"description":519,"useCases":520,"indexable":273},"DORA","Digital Operational Resilience Act for financial entities: ICT risk, incident reporting and third party risk, including AI providers.",66,{"id":522,"label":523,"issuer":524,"region":175,"url":525,"description":526,"useCases":527,"indexable":273},"uk-gdpr","UK GDPR","Information Commissioner's Office","https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/","The UK's version of the GDPR, including rules on solely automated decisions.",64,{"id":529,"label":530,"issuer":531,"region":175,"url":532,"description":533,"useCases":534,"indexable":273},"uk-consumer-duty","FCA Consumer Duty","Financial Conduct Authority","https://www.fca.org.uk/firms/consumer-duty","UK rules that require firms to deliver good outcomes for retail customers, including through automated channels.",47,{"id":536,"label":537,"issuer":538,"region":181,"url":539,"description":540,"useCases":541,"indexable":273},"mas-ai-risk-management","MAS AI risk management guidelines","Monetary Authority of Singapore","https://www.mas.gov.sg/news/media-releases/2025/mas-guidelines-for-artificial-intelligence-risk-management","Singapore's supervisory expectations for AI risk management at financial institutions, building on the FEAT principles.",36,{"id":166,"label":543,"issuer":180,"region":181,"url":182,"description":544,"useCases":352,"indexable":273},"APRA CPS 230","Australian operational risk standard covering critical operations and material service providers.",{"id":546,"label":547,"issuer":548,"region":225,"url":549,"description":550,"useCases":357,"indexable":273},"pci-dss","PCI DSS","PCI Security Standards Council","https://www.pcisecuritystandards.org/","Security standard for any system that stores, processes or transmits cardholder data.",{"id":552,"label":553,"issuer":554,"region":343,"url":555,"description":556,"useCases":357,"indexable":273},"us-sr-11-7","SR 11-7 model risk management","Federal Reserve and OCC","https://www.federalreserve.gov/boarddocs/srletters/2011/sr1107.htm","US supervisory guidance on model risk management, applied by banks to AI and machine learning models.",{"id":558,"label":559,"issuer":560,"region":175,"url":561,"description":562,"useCases":563,"indexable":273},"uk-atrs","UK Algorithmic Transparency Recording Standard","UK Government","https://www.gov.uk/government/collections/algorithmic-transparency-recording-standard-hub","Mandatory transparency records for algorithmic tools used by UK central government.",16,{"id":565,"label":566,"issuer":567,"region":225,"url":568,"description":569,"useCases":570,"indexable":273},"fatf-recommendations","FATF Recommendations","Financial Action Task Force","https://www.fatf-gafi.org/en/publications/Fatfrecommendations/Fatf-recommendations.html","Global standards for anti money laundering and counter terrorist financing that national rules implement.",15,{"id":572,"label":573,"issuer":174,"region":175,"url":574,"description":575,"useCases":576,"indexable":273},"eu-amlr","EU Anti Money Laundering Regulation","https://eur-lex.europa.eu/eli/reg/2024/1624/oj","Regulation (EU) 2024/1624: the single EU rulebook for customer due diligence, beneficial ownership and suspicious transaction reporting.",14,{"id":170,"label":578,"issuer":174,"region":175,"url":579,"description":580,"useCases":576,"indexable":273},"NIS2 Directive","https://eur-lex.europa.eu/eli/dir/2022/2555/oj","Directive (EU) 2022/2555 on cybersecurity for essential and important entities, including telecom networks, energy and public administration.",{"id":582,"label":583,"issuer":584,"region":343,"url":585,"description":586,"useCases":587,"indexable":273},"us-bsa","Bank Secrecy Act","FinCEN","https://www.fincen.gov/resources/statutes-and-regulations/bank-secrecy-act","US anti money laundering law: customer due diligence, suspicious activity reports and record keeping.",13,{"id":589,"label":590,"issuer":174,"region":175,"url":591,"description":592,"useCases":593,"indexable":273},"eu-accessibility-act","European Accessibility Act","https://eur-lex.europa.eu/eli/dir/2019/882/oj","Directive (EU) 2019/882: accessibility requirements for banking services, ecommerce and other digital services, applicable since June 2025.",12,{"id":595,"label":596,"issuer":597,"region":343,"url":598,"description":599,"useCases":593,"indexable":273},"hipaa","HIPAA","US Department of Health and Human Services","https://www.hhs.gov/hipaa/index.html","US rules for the privacy and security of protected health information.",{"id":601,"label":602,"issuer":603,"region":225,"url":604,"description":605,"useCases":593,"indexable":273},"telecom-consumer-rules","Telecom consumer protection rules","National telecom regulators","https://www.berec.europa.eu/","National rules on telecom contracts, switching, billing disputes and marketing consent.",{"id":607,"label":608,"issuer":174,"region":175,"url":609,"description":610,"useCases":611,"indexable":273},"eecc","European Electronic Communications Code","https://eur-lex.europa.eu/eli/dir/2018/1972/oj","Directive (EU) 2018/1972: consumer protection, contract, switching and security rules for telecom operators.",11,{"id":613,"label":614,"issuer":615,"region":343,"url":616,"description":617,"useCases":611,"indexable":273},"us-tcpa","Telephone Consumer Protection Act","Federal Communications Commission","https://www.fcc.gov/consumers/guides/stop-unwanted-robocalls-and-texts","US consent rules for automated and prerecorded calls and texts; the FCC has confirmed AI generated voices count as artificial voices.",{"id":619,"label":620,"issuer":538,"region":181,"url":621,"description":622,"useCases":623,"indexable":273},"mas-notice-626","MAS Notice 626","https://www.mas.gov.sg/regulation/notices/notice-626","Singapore's anti money laundering and counter terrorism financing requirements for banks.",10,{"id":625,"label":626,"issuer":174,"region":175,"url":627,"description":628,"useCases":623,"indexable":273},"mifid-ii","MiFID II","https://eur-lex.europa.eu/eli/dir/2014/65/oj","Directive 2014/65/EU on markets in financial instruments: suitability and appropriateness of advice, record keeping and product governance.",{"id":630,"label":631,"issuer":174,"region":175,"url":632,"description":633,"useCases":623,"indexable":273},"eu-psd2","PSD2","https://eur-lex.europa.eu/eli/dir/2015/2366/oj","Payment Services Directive 2: strong customer authentication, transaction risk analysis exemptions and open banking access.",{"id":635,"label":636,"issuer":637,"region":175,"url":638,"description":639,"useCases":640,"indexable":273},"eba-loan-origination","EBA Guidelines on loan origination and monitoring","European Banking Authority","https://www.eba.europa.eu/regulation-and-policy/credit-risk/guidelines-on-loan-origination-and-monitoring","Expectations for credit decisioning, including the use of automated models.",9,{"id":642,"label":643,"issuer":644,"region":343,"url":645,"description":646,"useCases":78,"indexable":273},"us-ecoa-reg-b","ECOA and Regulation B","Consumer Financial Protection Bureau","https://www.consumerfinance.gov/rules-policy/regulations/1002/9/","US fair lending rules, including specific reasons in adverse action notices, which also apply when credit decisions use AI models.",{"id":648,"label":649,"issuer":174,"region":175,"url":650,"description":651,"useCases":78,"indexable":273},"solvency-ii","Solvency II","https://eur-lex.europa.eu/eli/dir/2009/138/oj","Directive 2009/138/EC: risk based capital, governance and model requirements for insurers.",{"id":653,"label":654,"issuer":174,"region":175,"url":655,"description":656,"useCases":405,"indexable":273},"eu-idd","Insurance Distribution Directive","https://eur-lex.europa.eu/eli/dir/2016/97/oj","Directive (EU) 2016/97: conduct rules for selling insurance, including demands and needs testing and advice.",{"id":658,"label":659,"issuer":660,"region":661,"url":662,"description":663,"useCases":90,"indexable":273},"cbuae-ai-guidance","CBUAE guidance on AI and ML","Central Bank of the UAE","middle-east","https://www.centralbank.ae/","UAE central bank expectations for the enabling technologies, AI and machine learning used by licensed financial institutions.",{"id":665,"label":666,"issuer":667,"region":175,"url":668,"description":669,"useCases":65,"indexable":273},"pra-ss1-23","PRA SS1/23 model risk management","Prudential Regulation Authority","https://www.bankofengland.co.uk/prudential-regulation/publication/2023/may/model-risk-management-principles-for-banks-ss","UK model risk management principles for banks, covering AI and machine learning models.",{"id":671,"label":672,"issuer":673,"region":175,"url":674,"description":675,"useCases":65,"indexable":273},"uk-psr-app-reimbursement","UK APP scam reimbursement rules","Payment Systems Regulator","https://www.psr.org.uk/our-work/app-scams/","Mandatory reimbursement of authorised push payment scam victims by UK payment firms, which shifts scam losses onto banks.",{"id":677,"label":678,"issuer":679,"region":181,"url":680,"description":681,"useCases":370,"indexable":273},"au-scams-prevention-framework","Australian Scams Prevention Framework","Australian Treasury","https://treasury.gov.au/consultation/c2024-573813","Economy wide obligations for banks, telcos and digital platforms to prevent, detect, disrupt and respond to scams.",{"id":683,"label":684,"issuer":174,"region":175,"url":685,"description":686,"useCases":370,"indexable":273},"eu-mar","EU Market Abuse Regulation","https://eur-lex.europa.eu/eli/reg/2014/596/oj","Regulation (EU) 596/2014: insider dealing and market manipulation, including the duty to detect and report suspicious orders and transactions.",{"id":688,"label":689,"issuer":690,"region":343,"url":691,"description":692,"useCases":370,"indexable":273},"us-fcra","Fair Credit Reporting Act","Federal Trade Commission","https://www.ftc.gov/legal-library/browse/statutes/fair-credit-reporting-act","US rules on consumer reports, their accuracy and permissible use, relevant to credit scoring and screening.",1790598300341]