[{"data":1,"prerenderedAt":691},["ShallowReactive",2],{"uc-developer-coding-assistant":3,"uc-regulations":486},{"useCase":4,"evidence":198,"blitsAiDeployments":365,"benchmarks":366,"indicative":382,"related":385,"indexability":484,"includeUnpublished":204},{"title":5,"shortTitle":6,"seoTitle":7,"metaDescription":8,"status":9,"definition":10,"aliases":11,"industries":16,"functions":22,"patterns":24,"channels":26,"audience":28,"autonomy":29,"adoptionStage":30,"problem":31,"problemStats":32,"howItWorks":33,"valueDrivers":34,"kpis":37,"indicativeValue":42,"macroEstimates":76,"feasibility":77,"implementation":89,"risk":132,"blitsAi":175,"faq":177,"related":187,"datePublished":193,"dateModified":193,"lastVerified":193,"changelog":194,"slug":197},"AI coding assistant for software developers","Developer coding assistant","AI coding assistant for enterprise developers","AI coding assistants draft, test and review code under developer control. Bank of America reports efficiency gains over 20%, and ANZ and Accenture ran trials.","published","An AI assistant in the developer's IDE and code review flow that completes and generates code, explains unfamiliar modules, drafts unit tests and reviews pull requests for common defects, while generated code goes through the same review, testing and change controls as any other code.",[12,13,14,15],"developer copilot","AI pair programmer","code assistant","AI code review",[17,18,19,20,21],"cross-industry","banking","capital-markets","technology","professional-services",[23],"it-and-engineering",[25],"code-generation",[27],"internal-tools","employee-facing","copilot","mainstream","Large organizations run thousands of engineers, and a big share of their time goes to work that is\nnecessary but not differentiating: boilerplate, glue code, tests, reading code someone else wrote,\nand first pass review. Banks and insurers add a long tail of internal frameworks and legacy\nservices that new joiners have to learn before they are productive.\n\nCoding assistants take part of that load. The question for an engineering leader is no longer\nwhether developers will use them, but how to capture the gain safely: keeping proprietary code\nout of external training, stopping insecure or unlicensed code from reaching production, and\nmeasuring real delivery rather than lines of code accepted.",[],"1. **Inline completion and chat in the IDE.** The assistant suggests code as the developer types\n   and answers questions about the code base, using the open files and repository as context.\n2. **Tests and explanations.** Developers ask it to draft unit tests, explain a module or\n   propose a fix for a failing build.\n3. **Review assistance.** On a pull request it summarizes the change and flags likely defects,\n   which the human reviewer accepts or rejects.\n4. **Normal controls apply.** Generated code goes through peer review, static analysis, secret\n   and licence scanning, tests and change approval, exactly like human code.\n5. **Agentic tasks, carefully.** Newer tools can plan and apply multi file changes or run\n   commands. These should run in sandboxes with limited permissions, never directly against\n   production.",[35,36],"employee-productivity","speed",[38,39,40,41],"productivity-gain","hours-saved","employee-adoption","users-served",{"referenceOrg":43,"inputs":44,"formula":71,"currency":72,"period":73,"resultLabel":74,"caveat":75},"An engineering organization with 500 developers",[45,50,57,64],{"key":46,"label":47,"low":48,"high":48,"unit":46,"note":49},"developers","Developers with the assistant",500,"The reference organization.",{"key":51,"label":52,"low":53,"high":54,"unit":55,"note":56},"loadedCost","Fully loaded cost per developer",100000,150000,"USD per developer per year","Editorial assumption. Replace with your own blended cost, including contractors.",{"key":58,"label":59,"low":60,"high":61,"unit":62,"note":63},"affectedShare","Share of developer time spent on tasks the assistant helps with",0.3,0.5,"fraction of working time","Editorial assumption. Coding, tests and reading code, excluding meetings, design and incidents.",{"key":65,"label":66,"low":67,"high":68,"unit":69,"note":70},"timeSaved","Time saved on those tasks",0.1,0.2,"fraction of task time","Editorial assumption, set below the Bank of America and ANZ figures on this page (Bank of America reports efficiency gains of over 20%; ANZ's controlled experiment measured about 42% less time on algorithmic Python challenges). Most CME Group developers using Gemini Code Assist report at least 10.5 hours a month, which falls inside this range. The only field randomized trial, Accenture's, measured a different thing (8.69% more pull requests), so replace this with your own control group result.","developers * loadedCost * affectedShare * timeSaved","USD","per year","Developer capacity released","Released capacity, not cash: it only becomes value if the time goes into more delivery. It leaves out licence and review costs, the extra review effort generated code can create, and quality effects in either direction.",[],{"complexity":78,"complexityNote":79,"dataPrerequisites":80,"integrations":84},"low","Rolling out a commercial assistant is technically simple. The effort is in the contract and data terms, security review, secure configuration of repositories and secrets, training, and a measurement plan that looks at delivery rather than acceptance rates.",[81,82,83],"Repository access rules and a list of repositories excluded from assistant context","Secure coding standards and approved libraries the assistant should follow","Baseline delivery metrics (cycle time, pull request throughput, change failure rate)",[85,86,87,88],"IDEs and the source control platform","CI pipeline with static analysis, secret scanning and licence scanning","Identity provider for licence assignment and single sign on","Model gateway or vendor tenant with zero retention terms",{"steps":90,"guardrails":106,"humanInTheLoop":112,"kpisToInstrument":113,"failureModes":119},[91,94,97,100,103],{"title":92,"detail":93},"Settle data terms first","Choose a tenant where your code is not retained or used for training, confirm where prompts are processed, and record the tool as a third party service in your risk register.",{"title":95,"detail":96},"Pilot with a control group","Give the tool to a representative set of teams and compare them with similar teams without it over several weeks, on delivery metrics rather than surveys alone.",{"title":98,"detail":99},"Strengthen the pipeline","Make secret scanning, dependency and licence checks and static analysis mandatory gates before merge, since more code will arrive faster.",{"title":101,"detail":102},"Train reviewers as well as authors","Teach engineers to treat suggestions as untrusted input, to check generated tests actually test something, and to reject code they do not understand.",{"title":104,"detail":105},"Scale and keep measuring","Roll out by team, track adoption and delivery metrics per cohort, and revisit settings when new agentic features arrive.",[107,108,109,110,111],"Zero retention and no training on the organization's code, confirmed contractually","Generated code passes the same review, testing and change approval as human code","Mandatory secret, dependency, licence and static analysis scanning before merge","Agentic features run in sandboxes without production credentials","Sensitive repositories excluded from assistant context where required","A developer accepts or rejects every suggestion and remains the author of record. A second engineer reviews every change before merge, and release managers approve production changes as before. Agent generated multi file changes are reviewed like a new colleague's first pull request.",[114,115,116,117,118],"Pull request throughput and lead time per team, compared with a control group","Change failure rate and escaped defects","Security findings per thousand lines in generated versus human code","Weekly active users among licensed developers","Developer satisfaction, surveyed quarterly",[120,123,126,129],{"title":121,"detail":122},"Measuring the wrong thing","Acceptance rates and lines generated rise while delivery does not. Measure throughput, lead time and quality against a control group.",{"title":124,"detail":125},"Faster insecure code","Suggestions reproduce insecure patterns or hard coded secrets. Scanning gates and reviewer training catch them; the tool alone does not.",{"title":127,"detail":128},"Source code leakage","Engineers paste proprietary code into public chat tools when the approved tool is weak. Provide a good approved tool and block the alternatives.",{"title":130,"detail":131},"Agents with too much reach","An agent with shell or database access acts outside its task. Limit permissions and never give it production credentials.",{"euAiAct":133,"regulations":136,"guidance":142,"controls":160,"incidents":166},{"tier":134,"basis":135},"minimal","A coding assistant used by developers is not a prohibited practice under Article 5 and is not listed in Annex III. Developers know they are working with an AI tool, so the Article 50 disclosure duty has no practical effect for the deploying organization, and the marking of generated content under Article 50(2) falls on the tool's provider. What remains is AI literacy (Article 4). Using an AI system to monitor or evaluate individual developers' performance would fall under Annex III point 4(b), and the software the assistant helps build may itself fall under the Act.",[137,138,139,140,141],"eu-ai-act","dora","iso-42001","nist-ai-rmf","apra-cps-230",[143,149,155],{"title":144,"issuer":145,"region":146,"url":147,"note":148},"SP 800-218, Secure Software Development Framework (SSDF) Version 1.1","NIST","north-america","https://csrc.nist.gov/pubs/sp/800/218/final","Baseline secure software development practices, such as code review, testing and vulnerability response, that apply to generated code as much as to code written by hand.",{"title":150,"issuer":151,"region":152,"url":153,"note":154},"Guidelines for secure AI system development","UK National Cyber Security Centre","europe","https://www.ncsc.gov.uk/collection/guidelines-secure-ai-system-development","Guidelines for providers of AI systems in four areas (secure design, development, deployment, and operation and maintenance), relevant when you build your own tooling or agents around the assistant.",{"title":156,"issuer":157,"region":152,"url":158,"note":159},"Article 4, AI literacy","European Union","https://artificialintelligenceact.eu/article/4/","Providers and deployers must take measures on the AI literacy of staff who use AI systems (the amended wording shown on this page asks them to support it rather than ensure a sufficient level). Here that means training developers on the tool's limits.",[161,162,163,164,165],"Third party risk assessment and register entry for the assistant vendor","Contractual zero retention and data location terms","Mandatory scanning gates in the CI pipeline","Developer training on reviewing generated code","Periodic review of agent permissions and repository exclusions",[167,171],{"title":168,"url":169,"note":170},"Incident 768: ChatGPT reportedly implicated in Samsung data leak of source code and meeting notes","https://incidentdatabase.ai/cite/768/","Samsung engineers were reported to have leaked source code and internal meeting notes in March 2023 by entering them into ChatGPT for help with their work. It shows why an approved tool with proper data terms matters.",{"title":172,"url":173,"note":174},"Incident 1152: LLM-Driven Replit Agent Reportedly Executed Unauthorized Destructive Commands During Code Freeze, Leading to Loss of Production Data","https://incidentdatabase.ai/cite/1152/","An agentic coding tool with access to a live production database reportedly deleted it during a code freeze, despite instructions not to change code without permission. Agentic features need sandboxes and least privilege.",{"howToBuild":176},"Blits.ai is not an IDE coding assistant, and a dedicated tool is the right choice for inline\ncompletion and code review. Where Blits.ai fits is the engineering knowledge around the code: an\n**AI agent** grounded in a **knowledge base** of internal standards, architecture decisions,\nrunbooks and API documentation, with hybrid retrieval, available to engineers in **Microsoft\nTeams** or **Slack**. The integration catalog includes GitHub, Jira and Confluence.\n\nFor repeatable engineering tasks, such as drafting release notes or checking a change against\ninternal standards, **agentic workflows** run with **human in the loop approval** and a\n**tool execution policy**, and every run keeps an audit trail. **PII masking** applies at the\ngateway before text reaches a model, input and output **guardrails** check content, **model\nagnostic** routing lets the organization choose\nwhich model sees its code, and EU or UAE data residency is available.",[178,181,184],{"question":179,"answer":180},"How much faster do developers get with a coding assistant?","Published results vary widely with how they are measured. Bank of America reports efficiency gains of over 20% for its developers, Accenture's randomized trial with GitHub saw 8.69% more pull requests, and ANZ measured about 42% less time on algorithmic Python challenges. Set exercises tend to overstate everyday gains, so measure your own teams against a control group.",{"question":182,"answer":183},"Does our code train the vendor's model?","It depends on the vendor, the plan and the contract, and terms differ between them. Confirm in writing that your code is not used for training and how long prompts are retained, check where prompts are processed, and treat the tool as a material third party service where your regulator expects that.",{"question":185,"answer":186},"Is generated code a regulatory problem for a bank?","Not in itself. Rules such as DORA require ICT change management, testing and security controls, and these apply whoever or whatever wrote the code. The risk is the pipeline receiving more code than it can review, so strengthen scanning and review before scaling.",[188,189,190,191,192],"legacy-code-modernization","developer-api-integration-assistant","aiops-incident-triage","governed-text-to-sql-analytics","enterprise-knowledge-search","2026-09-27",[195],{"date":193,"note":196},"First published","developer-coding-assistant",[199,232,266,291,315,342],{"title":200,"useCases":201,"organization":202,"vendors":206,"summary":207,"stage":208,"year":209,"channels":210,"languages":211,"metrics":213,"outcomeDisclosed":221,"sources":222,"verification":226,"grade":229,"id":230,"organizationSlug":231},"Bank of America: generative AI coding assistant for software developers",[197],{"name":203,"anonymized":204,"country":205,"region":146,"industry":18},"Bank of America",false,"US",[],"Bank of America software developers use a generative AI tool that helps them write and optimize code. The bank reported the efficiency gain in its April 2025 update on how its workforce uses AI, alongside its internal assistants and contact centre tools. The bank does not name the underlying model or vendor.","production",2025,[27],[212],"en",[214],{"kpi":38,"value":215,"unit":216,"qualifier":217,"claimant":218,"quote":219,"sourceUrl":220},20,"percent","at-least","organization","Coding assistance – Bank of America software developers are using a GenAI-based tool to assist with code writing and optimization, through which they have experienced efficiency gains of over 20%.","https://newsroom.bankofamerica.com/content/newsroom/press-releases/2025/04/ai-adoption-by-bofa-s-global-workforce-improves-productivity--cl.html",true,[223],{"url":220,"title":224,"publisher":203,"date":225},"AI Adoption by BofA's Global Workforce Improves Productivity, Client Service","2025-04-08",{"level":227,"checkedAt":228},"source-verified","2026-09-26","B","bank-of-america-coding-assistant","bank-of-america",{"title":233,"useCases":234,"organization":235,"vendors":239,"summary":243,"stage":208,"year":244,"channels":245,"languages":246,"metrics":247,"outcomeDisclosed":221,"sources":255,"verification":263,"grade":229,"id":264,"organizationSlug":265},"ANZ Bank: controlled experiment and rollout of GitHub Copilot to engineers",[197],{"name":236,"anonymized":204,"country":237,"region":238,"industry":18},"ANZ","AU","asia-pacific",[240],{"name":241,"role":242},"GitHub","platform","ANZ, which employs over 5,000 engineers, ran a six week experiment with GitHub Copilot from June to July 2023: after two weeks of preparation, over 100 participants were split at random into a control group and a Copilot group that solved the same algorithmic Python challenges. The Copilot group took markedly less time and produced code with fewer code smells and bugs, while the effect on security was inconclusive. By the time of writing about 1,000 engineers were using Copilot. The study was written by ANZ staff and published on arXiv.",2024,[27],[212],[248],{"kpi":38,"value":249,"unit":216,"qualifier":250,"period":251,"baseline":252,"claimant":218,"quote":253,"sourceUrl":254},42.36,"exact","two week A/B test on algorithmic Python challenges, self reported time","Mean time per challenge in the control group without Copilot","This study shows that Copilot improves the productivity of ANZ engineers by 42.36% on an average.","https://arxiv.org/pdf/2402.05636",[256,261],{"url":257,"title":258,"publisher":259,"date":260},"https://arxiv.org/abs/2402.05636","The Impact of AI Tool on Engineering at ANZ Bank An Empirical Study on GitHub Copilot within Corporate Environment","arXiv","2024-02-08",{"url":254,"title":262,"publisher":259},"The Impact of AI Tool on Engineering at ANZ Bank (full paper, PDF)",{"level":227,"checkedAt":228},"anz-github-copilot-study",null,{"title":267,"useCases":268,"organization":269,"vendors":272,"summary":273,"stage":274,"year":244,"channels":275,"languages":276,"metrics":277,"outcomeDisclosed":204,"sources":278,"verification":288,"grade":229,"id":289,"organizationSlug":290},"Citigroup: generative AI coding tools for 30,000 developers",[197],{"name":270,"anonymized":204,"country":205,"region":271,"industry":18},"Citigroup","global",[],"On Citi's fourth quarter 2024 earnings call, CEO Jane Fraser said the bank had armed 30,000 developers with AI tools to write code and launched two AI platforms for 143,000 colleagues. CIO Dive reported the same rollout as generative AI coding tools. No productivity or quality figures for the coding tools are disclosed, and the vendors are not named.","scaled",[27],[212],[],[279,283],{"url":280,"title":281,"publisher":270,"date":282},"https://www.citigroup.com/rcs/citigpa/storage/public/Earnings/Q42024/4Q24-Earnings-Transcript.pdf","Citi Fourth Quarter 2024 Earnings Call (transcript)","2025-01-15",{"url":284,"title":285,"publisher":286,"date":287},"https://www.ciodive.com/news/bank-technology-generative-ai-coding-deepseek-accenture/738300/","Banks fire up coding assistants as AI costs plummet","CIO Dive","2025-01-24",{"level":227,"checkedAt":193},"citigroup-developer-coding-tools","citi",{"title":292,"useCases":293,"organization":294,"vendors":296,"summary":299,"stage":208,"year":244,"channels":300,"languages":301,"metrics":302,"outcomeDisclosed":221,"sources":308,"verification":313,"grade":229,"id":314,"organizationSlug":265},"Meta: TestGen-LLM had 73% of its generated unit tests accepted for production during internal test events",[197],{"name":295,"anonymized":204,"country":205,"region":271,"industry":20},"Meta",[297],{"name":295,"role":298},"in-house","Meta built TestGen-LLM, a tool that uses large language models to draft and improve unit tests. During Instagram and Facebook test events, it improved 11.5% of all classes it was applied to, and 73% of its recommended test improvements were accepted by Meta software engineers for production deployment.",[27],[],[303],{"kpi":304,"value":305,"unit":216,"qualifier":250,"claimant":218,"quote":306,"sourceUrl":307},"accuracy",73,"During Meta's Instagram and Facebook test-a-thons, it improved 11.5% of all classes to which it was applied, with 73% of its recommendations being accepted for production deployment by Meta software engineers.","https://arxiv.org/abs/2402.09171",[309],{"url":307,"title":310,"publisher":311,"date":312},"Automated Unit Test Improvement using Large Language Models at Meta","Meta (arXiv, FSE 2024)","2024-02-14",{"level":227,"checkedAt":193},"meta-testgen-llm-unit-tests",{"title":316,"useCases":317,"organization":318,"vendors":320,"summary":323,"stage":208,"year":209,"channels":324,"languages":325,"metrics":326,"outcomeDisclosed":221,"sources":334,"verification":339,"grade":340,"id":341,"organizationSlug":265},"CME Group: Gemini Code Assist for developers",[197],{"name":319,"anonymized":204,"country":205,"region":146,"industry":19},"CME Group",[321],{"name":322,"role":242},"Google Cloud","CME Group, which operates the Chicago Mercantile Exchange, gave its developers Gemini Code Assist. Google Cloud reports that most developers using it say they gain at least 10.5 hours a month.",[27],[212],[327],{"kpi":39,"value":328,"unit":329,"qualifier":217,"period":330,"claimant":331,"quote":332,"sourceUrl":333},10.5,"hours","per developer per month, self reported","vendor","CME Group, which operates the Chicago Mercantile Exchange, says most developers using Gemini Code Assist report a productivity gain of at least 10.5 hours a month.","https://cloud.google.com/transform/101-real-world-generative-ai-use-cases-from-industry-leaders",[335],{"url":333,"title":336,"publisher":322,"date":337,"archivedUrl":338},"Real world gen AI use cases from the world's leading organizations","2025-04-15","https://web.archive.org/web/20250415211336/https://cloud.google.com/transform/101-real-world-generative-ai-use-cases-from-industry-leaders",{"level":227,"checkedAt":193},"C","cme-group-gemini-code-assist",{"title":343,"useCases":344,"organization":345,"vendors":348,"summary":350,"stage":208,"year":244,"channels":351,"languages":352,"metrics":353,"outcomeDisclosed":221,"sources":359,"verification":363,"grade":340,"id":364,"organizationSlug":265},"Accenture: randomized controlled trial of GitHub Copilot",[197],{"name":346,"anonymized":204,"country":347,"region":271,"industry":21},"Accenture","IE",[349],{"name":241,"role":242},"GitHub and Accenture ran a randomized controlled trial in which Accenture developers were randomly given GitHub Copilot or not, and measured DevOps telemetry such as pull requests and build success. The Copilot group opened more pull requests and saw many more successful builds, and surveyed developers reported less mental effort on repetitive tasks. GitHub also ran a company wide adoption analysis of installation and suggestion acceptance at Accenture.",[27],[212],[354],{"kpi":38,"value":355,"unit":216,"qualifier":250,"baseline":356,"claimant":331,"quote":357,"sourceUrl":358},8.69,"Pull requests per developer in the control group","Ultimately, an increase in pull requests represents an increase in value delivered, and Accenture developers saw an 8.69% increase in pull requests.","https://github.blog/news-insights/research/research-quantifying-github-copilots-impact-in-the-enterprise-with-accenture/",[360],{"url":358,"title":361,"publisher":241,"date":362},"Research: Quantifying GitHub Copilot's impact in the enterprise with Accenture","2024-05-13",{"level":227,"checkedAt":193},"accenture-github-copilot-trial",0,[367,377],{"kpi":38,"label":368,"unit":216,"aggregate":221,"higherIsBetter":221,"n":369,"nUpTo":365,"median":215,"min":355,"max":249,"byClaimant":370,"vendorOnly":204,"points":373},"Productivity gain",3,{"organization":371,"vendor":372,"regulator":365,"independent":365},2,1,[374,375,376],{"evidenceId":264,"organization":236,"value":249,"qualifier":250,"claimant":218,"grade":229,"pooled":221},{"evidenceId":230,"organization":203,"value":215,"qualifier":217,"claimant":218,"grade":229,"pooled":221},{"evidenceId":364,"organization":346,"value":355,"qualifier":250,"claimant":331,"grade":340,"pooled":221},{"kpi":39,"label":378,"unit":329,"aggregate":204,"higherIsBetter":221,"n":372,"nUpTo":365,"median":328,"min":328,"max":328,"byClaimant":379,"vendorOnly":221,"points":380},"Hours saved",{"organization":365,"vendor":372,"regulator":365,"independent":365},[381],{"evidenceId":341,"organization":319,"value":328,"qualifier":217,"claimant":331,"grade":340,"pooled":221},{"low":383,"high":384},1500000,7500000,[386,411,436,456,471],{"slug":188,"title":387,"shortTitle":388,"definition":389,"status":9,"industries":390,"functions":392,"patterns":393,"audience":28,"autonomy":29,"adoptionStage":396,"evidenceCount":397,"publicEvidenceCount":398,"organizations":399,"bestGrade":229,"headline":405,"lastVerified":193,"indexable":221},"AI for legacy code modernization","Legacy code modernization","AI that reads legacy code such as COBOL, PL/I or old Java, explains what each program does, maps its data flows and dependencies, drafts the equivalent modern code or specification, and generates the regression tests needed to prove the new system behaves like the old one.",[17,18,19,391,20],"automotive",[23],[25,394,395],"summarization","agentic-workflow","early-adopters",6,5,[400,401,402,403,404],"Airbnb","Amazon","Google","Morgan Stanley","Toyota Motor Europe",{"kpi":406,"label":407,"unit":216,"n":372,"nUpTo":365,"kind":408,"value":409,"qualifier":410,"claimant":218,"organization":402,"vendorReported":204},"processing-time-reduction","Cycle time reduction","reported",50,"approximately",{"slug":189,"title":412,"shortTitle":413,"definition":414,"status":9,"industries":415,"functions":417,"patterns":420,"audience":423,"autonomy":424,"adoptionStage":396,"segment":425,"evidenceCount":426,"publicEvidenceCount":426,"organizations":427,"bestGrade":229,"headline":432,"lastVerified":193,"indexable":221},"AI assistant for developers integrating a company's APIs","API integration assistant","An AI assistant on a developer portal and in its documentation that answers integration questions, recommends the right endpoints, helps debug connections and generates sample calls, grounded in the API catalogue, reference docs and test material, so clients and partners integrate faster with fewer support tickets.",[17,18,416,20],"payments",[23,418,419],"customer-service","onboarding-and-kyc",[421,422,25],"rag-knowledge-assistant","conversational-agent","customer-facing","assist","specialized-businesses",4,[428,429,430,431],"CircleCI","Mapbox","monday.com","U.S. Bank",{"kpi":433,"label":434,"unit":216,"n":372,"nUpTo":365,"kind":408,"value":435,"qualifier":250,"claimant":218,"organization":429,"vendorReported":204},"contact-deflection","Contact deflection",30,{"slug":190,"title":437,"shortTitle":438,"definition":439,"status":9,"industries":440,"functions":442,"patterns":445,"audience":28,"autonomy":29,"adoptionStage":396,"evidenceCount":397,"publicEvidenceCount":398,"organizations":448,"bestGrade":229,"headline":452,"lastVerified":193,"indexable":221},"AI for IT incident triage and root cause analysis (AIOps)","AIOps incident triage","AI that turns a flood of monitoring alerts into one probable incident, routes it to the right team, proposes likely root causes and remediation from runbooks and past incidents, and drafts the stakeholder updates and the post incident review, while an engineer authorizes every change.",[17,18,20,441,416],"telecommunications",[23,443,444],"operations","risk-management",[446,447,394,421,395],"anomaly-detection","classification-and-routing",[402,295,449,450,451],"Microsoft","Mizuho Financial Group","TD Bank",{"kpi":304,"label":453,"unit":216,"n":369,"nUpTo":365,"kind":454,"value":455,"qualifier":250,"claimant":265,"organization":265,"vendorReported":204},"Accuracy","median",90,{"slug":191,"title":457,"shortTitle":458,"definition":459,"status":9,"industries":460,"functions":464,"patterns":466,"audience":28,"autonomy":424,"adoptionStage":396,"evidenceCount":369,"publicEvidenceCount":369,"organizations":467,"bestGrade":229,"headline":265,"lastVerified":193,"indexable":221},"Governed text to SQL analytics assistant","Governed SQL analytics","An assistant that turns a business user's plain language question into a query against governed data, runs it under that user's own data permissions and returns the table or chart together with the SQL and the tables used, so routine ad hoc questions no longer queue for the data team.",[17,18,461,462,20,463],"insurance","retail-and-ecommerce","pharma-and-life-sciences",[465,23],"analytics-and-reporting",[422,25,421],[468,469,470],"Bayer","LinkedIn","Uber Technologies",{"slug":192,"title":472,"shortTitle":473,"definition":474,"status":9,"industries":475,"functions":478,"patterns":480,"audience":28,"autonomy":424,"adoptionStage":30,"evidenceCount":426,"publicEvidenceCount":426,"organizations":481,"bestGrade":229,"headline":265,"lastVerified":193,"indexable":221},"AI enterprise knowledge search for employees","Enterprise knowledge search","An assistant that lets any employee ask a question in plain language and get a synthesized answer from the organization's own policies, procedures, product manuals and research, with citations to the source documents and only from documents the employee is allowed to see.",[17,18,476,461,477,21],"wealth-and-asset-management","government",[479,443,418],"knowledge-management",[421,422,394],[203,403,482,483],"SIGNAL IDUNA","Wells Fargo",{"indexable":221,"reasons":485},[],[487,492,498,504,509,514,521,528,535,541,547,553,560,567,573,578,585,591,597,603,609,615,621,626,631,638,645,650,655,662,668,674,680,685],{"id":137,"label":488,"issuer":157,"region":152,"url":489,"description":490,"useCases":491,"indexable":221},"EU AI Act","https://eur-lex.europa.eu/eli/reg/2024/1689/oj","Regulation (EU) 2024/1689: risk based rules for AI systems, with obligations for high risk systems listed in Annex III and transparency duties under Article 50.",197,{"id":493,"label":494,"issuer":157,"region":152,"url":495,"description":496,"useCases":497,"indexable":221},"gdpr","GDPR","https://eur-lex.europa.eu/eli/reg/2016/679/oj","General Data Protection Regulation, including Article 22 on decisions based solely on automated processing.",180,{"id":139,"label":499,"issuer":500,"region":271,"url":501,"description":502,"useCases":503,"indexable":221},"ISO/IEC 42001","ISO and IEC","https://www.iso.org/standard/81230.html","The international management system standard for AI.",110,{"id":140,"label":505,"issuer":145,"region":146,"url":506,"description":507,"useCases":508,"indexable":221},"NIST AI Risk Management Framework","https://www.nist.gov/itl/ai-risk-management-framework","Voluntary US framework to map, measure, manage and govern AI risk, with a generative AI profile.",83,{"id":138,"label":510,"issuer":157,"region":152,"url":511,"description":512,"useCases":513,"indexable":221},"DORA","https://eur-lex.europa.eu/eli/reg/2022/2554/oj","Digital Operational Resilience Act for financial entities: ICT risk, incident reporting and third party risk, including AI providers.",66,{"id":515,"label":516,"issuer":517,"region":152,"url":518,"description":519,"useCases":520,"indexable":221},"uk-gdpr","UK GDPR","Information Commissioner's Office","https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/","The UK's version of the GDPR, including rules on solely automated decisions.",64,{"id":522,"label":523,"issuer":524,"region":152,"url":525,"description":526,"useCases":527,"indexable":221},"uk-consumer-duty","FCA Consumer Duty","Financial Conduct Authority","https://www.fca.org.uk/firms/consumer-duty","UK rules that require firms to deliver good outcomes for retail customers, including through automated channels.",47,{"id":529,"label":530,"issuer":531,"region":238,"url":532,"description":533,"useCases":534,"indexable":221},"mas-ai-risk-management","MAS AI risk management guidelines","Monetary Authority of Singapore","https://www.mas.gov.sg/news/media-releases/2025/mas-guidelines-for-artificial-intelligence-risk-management","Singapore's supervisory expectations for AI risk management at financial institutions, building on the FEAT principles.",36,{"id":141,"label":536,"issuer":537,"region":238,"url":538,"description":539,"useCases":540,"indexable":221},"APRA CPS 230","Australian Prudential Regulation Authority","https://www.apra.gov.au/operational-risk-management","Australian operational risk standard covering critical operations and material service providers.",25,{"id":542,"label":543,"issuer":544,"region":271,"url":545,"description":546,"useCases":215,"indexable":221},"pci-dss","PCI DSS","PCI Security Standards Council","https://www.pcisecuritystandards.org/","Security standard for any system that stores, processes or transmits cardholder data.",{"id":548,"label":549,"issuer":550,"region":146,"url":551,"description":552,"useCases":215,"indexable":221},"us-sr-11-7","SR 11-7 model risk management","Federal Reserve and OCC","https://www.federalreserve.gov/boarddocs/srletters/2011/sr1107.htm","US supervisory guidance on model risk management, applied by banks to AI and machine learning models.",{"id":554,"label":555,"issuer":556,"region":152,"url":557,"description":558,"useCases":559,"indexable":221},"uk-atrs","UK Algorithmic Transparency Recording Standard","UK Government","https://www.gov.uk/government/collections/algorithmic-transparency-recording-standard-hub","Mandatory transparency records for algorithmic tools used by UK central government.",16,{"id":561,"label":562,"issuer":563,"region":271,"url":564,"description":565,"useCases":566,"indexable":221},"fatf-recommendations","FATF Recommendations","Financial Action Task Force","https://www.fatf-gafi.org/en/publications/Fatfrecommendations/Fatf-recommendations.html","Global standards for anti money laundering and counter terrorist financing that national rules implement.",15,{"id":568,"label":569,"issuer":157,"region":152,"url":570,"description":571,"useCases":572,"indexable":221},"eu-amlr","EU Anti Money Laundering Regulation","https://eur-lex.europa.eu/eli/reg/2024/1624/oj","Regulation (EU) 2024/1624: the single EU rulebook for customer due diligence, beneficial ownership and suspicious transaction reporting.",14,{"id":574,"label":575,"issuer":157,"region":152,"url":576,"description":577,"useCases":572,"indexable":221},"nis2","NIS2 Directive","https://eur-lex.europa.eu/eli/dir/2022/2555/oj","Directive (EU) 2022/2555 on cybersecurity for essential and important entities, including telecom networks, energy and public administration.",{"id":579,"label":580,"issuer":581,"region":146,"url":582,"description":583,"useCases":584,"indexable":221},"us-bsa","Bank Secrecy Act","FinCEN","https://www.fincen.gov/resources/statutes-and-regulations/bank-secrecy-act","US anti money laundering law: customer due diligence, suspicious activity reports and record keeping.",13,{"id":586,"label":587,"issuer":157,"region":152,"url":588,"description":589,"useCases":590,"indexable":221},"eu-accessibility-act","European Accessibility Act","https://eur-lex.europa.eu/eli/dir/2019/882/oj","Directive (EU) 2019/882: accessibility requirements for banking services, ecommerce and other digital services, applicable since June 2025.",12,{"id":592,"label":593,"issuer":594,"region":146,"url":595,"description":596,"useCases":590,"indexable":221},"hipaa","HIPAA","US Department of Health and Human Services","https://www.hhs.gov/hipaa/index.html","US rules for the privacy and security of protected health information.",{"id":598,"label":599,"issuer":600,"region":271,"url":601,"description":602,"useCases":590,"indexable":221},"telecom-consumer-rules","Telecom consumer protection rules","National telecom regulators","https://www.berec.europa.eu/","National rules on telecom contracts, switching, billing disputes and marketing consent.",{"id":604,"label":605,"issuer":157,"region":152,"url":606,"description":607,"useCases":608,"indexable":221},"eecc","European Electronic Communications Code","https://eur-lex.europa.eu/eli/dir/2018/1972/oj","Directive (EU) 2018/1972: consumer protection, contract, switching and security rules for telecom operators.",11,{"id":610,"label":611,"issuer":612,"region":146,"url":613,"description":614,"useCases":608,"indexable":221},"us-tcpa","Telephone Consumer Protection Act","Federal Communications Commission","https://www.fcc.gov/consumers/guides/stop-unwanted-robocalls-and-texts","US consent rules for automated and prerecorded calls and texts; the FCC has confirmed AI generated voices count as artificial voices.",{"id":616,"label":617,"issuer":531,"region":238,"url":618,"description":619,"useCases":620,"indexable":221},"mas-notice-626","MAS Notice 626","https://www.mas.gov.sg/regulation/notices/notice-626","Singapore's anti money laundering and counter terrorism financing requirements for banks.",10,{"id":622,"label":623,"issuer":157,"region":152,"url":624,"description":625,"useCases":620,"indexable":221},"mifid-ii","MiFID II","https://eur-lex.europa.eu/eli/dir/2014/65/oj","Directive 2014/65/EU on markets in financial instruments: suitability and appropriateness of advice, record keeping and product governance.",{"id":627,"label":628,"issuer":157,"region":152,"url":629,"description":630,"useCases":620,"indexable":221},"eu-psd2","PSD2","https://eur-lex.europa.eu/eli/dir/2015/2366/oj","Payment Services Directive 2: strong customer authentication, transaction risk analysis exemptions and open banking access.",{"id":632,"label":633,"issuer":634,"region":152,"url":635,"description":636,"useCases":637,"indexable":221},"eba-loan-origination","EBA Guidelines on loan origination and monitoring","European Banking Authority","https://www.eba.europa.eu/regulation-and-policy/credit-risk/guidelines-on-loan-origination-and-monitoring","Expectations for credit decisioning, including the use of automated models.",9,{"id":639,"label":640,"issuer":641,"region":146,"url":642,"description":643,"useCases":644,"indexable":221},"us-ecoa-reg-b","ECOA and Regulation B","Consumer Financial Protection Bureau","https://www.consumerfinance.gov/rules-policy/regulations/1002/9/","US fair lending rules, including specific reasons in adverse action notices, which also apply when credit decisions use AI models.",8,{"id":646,"label":647,"issuer":157,"region":152,"url":648,"description":649,"useCases":644,"indexable":221},"solvency-ii","Solvency II","https://eur-lex.europa.eu/eli/dir/2009/138/oj","Directive 2009/138/EC: risk based capital, governance and model requirements for insurers.",{"id":651,"label":652,"issuer":157,"region":152,"url":653,"description":654,"useCases":397,"indexable":221},"eu-idd","Insurance Distribution Directive","https://eur-lex.europa.eu/eli/dir/2016/97/oj","Directive (EU) 2016/97: conduct rules for selling insurance, including demands and needs testing and advice.",{"id":656,"label":657,"issuer":658,"region":659,"url":660,"description":661,"useCases":398,"indexable":221},"cbuae-ai-guidance","CBUAE guidance on AI and ML","Central Bank of the UAE","middle-east","https://www.centralbank.ae/","UAE central bank expectations for the enabling technologies, AI and machine learning used by licensed financial institutions.",{"id":663,"label":664,"issuer":665,"region":152,"url":666,"description":667,"useCases":426,"indexable":221},"pra-ss1-23","PRA SS1/23 model risk management","Prudential Regulation Authority","https://www.bankofengland.co.uk/prudential-regulation/publication/2023/may/model-risk-management-principles-for-banks-ss","UK model risk management principles for banks, covering AI and machine learning models.",{"id":669,"label":670,"issuer":671,"region":152,"url":672,"description":673,"useCases":426,"indexable":221},"uk-psr-app-reimbursement","UK APP scam reimbursement rules","Payment Systems Regulator","https://www.psr.org.uk/our-work/app-scams/","Mandatory reimbursement of authorised push payment scam victims by UK payment firms, which shifts scam losses onto banks.",{"id":675,"label":676,"issuer":677,"region":238,"url":678,"description":679,"useCases":369,"indexable":221},"au-scams-prevention-framework","Australian Scams Prevention Framework","Australian Treasury","https://treasury.gov.au/consultation/c2024-573813","Economy wide obligations for banks, telcos and digital platforms to prevent, detect, disrupt and respond to scams.",{"id":681,"label":682,"issuer":157,"region":152,"url":683,"description":684,"useCases":369,"indexable":221},"eu-mar","EU Market Abuse Regulation","https://eur-lex.europa.eu/eli/reg/2014/596/oj","Regulation (EU) 596/2014: insider dealing and market manipulation, including the duty to detect and report suspicious orders and transactions.",{"id":686,"label":687,"issuer":688,"region":146,"url":689,"description":690,"useCases":369,"indexable":221},"us-fcra","Fair Credit Reporting Act","Federal Trade Commission","https://www.ftc.gov/legal-library/browse/statutes/fair-credit-reporting-act","US rules on consumer reports, their accuracy and permissible use, relevant to credit scoring and screening.",1790598297744]