[{"data":1,"prerenderedAt":685},["ShallowReactive",2],{"uc-synthetic-test-data-generation":3,"uc-regulations":478},{"useCase":4,"evidence":197,"blitsAiDeployments":342,"benchmarks":372,"indicative":392,"related":395,"indexability":476,"includeUnpublished":203},{"title":5,"shortTitle":6,"seoTitle":7,"metaDescription":8,"status":9,"definition":10,"aliases":11,"industries":16,"functions":21,"patterns":24,"channels":27,"audience":30,"autonomy":31,"adoptionStage":32,"problem":33,"problemStats":34,"howItWorks":35,"valueDrivers":36,"kpis":41,"indicativeValue":46,"macroEstimates":82,"feasibility":83,"implementation":96,"risk":142,"blitsAi":171,"faq":173,"related":186,"datePublished":191,"dateModified":191,"lastVerified":192,"changelog":193,"slug":196},"AI for synthetic test data generation","Synthetic test data generation","Synthetic test data generation with AI","AI generates realistic test data without real personal data. Patterson Dental cut test data preparation by 75%, and Merkur Versicherung cut time to data to one day.","published","AI that generates realistic synthetic datasets, such as customers, transactions, documents and conversations, which keep the structure and statistical properties of production data without containing real personal data, so teams can test software, train and validate models and run demos safely.",[12,13,14,15],"synthetic data generation","privacy safe test data","synthetic test data management","AI generated test data",[17,18,19,20],"cross-industry","banking","healthcare","insurance",[22,23],"it-and-engineering","analytics-and-reporting",[25,26],"synthetic-data-generation","content-generation",[28,29],"internal-tools","api","back-office","supervised-agent","early-adopters","Every new system, release and model needs data that looks like the real thing: customers with\nplausible histories, transactions with realistic patterns, claims, statements and conversations.\nThe easy answer is to copy production into test environments, which puts personal and confidential\ndata in places with weaker controls, in the hands of contractors and offshore teams, and in the\ntraining sets of models. Some organizations have sealed production off from development\naltogether, as Kin Insurance did, and data protection law makes such copies hard to justify.\n\nThe alternatives each have a cost. Hand written mock data is safe but thin, so tests pass that\nwould fail on real data. Masking production data keeps realism but can still leave people\nidentifiable, and preparing a usable copy by hand is slow: Patterson Dental needed 2.5 hours per\ndataset before it automated the work. Rare but important\ncases, such as fraud patterns or unusual products, are often missing entirely. Synthetic data\ngeneration aims to give teams realistic, referentially consistent data on demand, with a measured\nprivacy risk.",[],"1. **Profile the source.** A generator learns the schema, relationships and statistical\n   distributions of a production dataset inside the secure environment, or works from a schema and\n   business rules when no production data may be used.\n2. **Generate.** It produces new records (customers, accounts, transactions, claims, documents or\n   conversation transcripts) that follow the same patterns and keep keys consistent across tables,\n   with the option to add rare cases such as fraud or edge conditions on purpose.\n3. **Measure privacy, utility and fidelity.** Automated checks confirm that no generated record\n   copies a real one, test for reidentification risk and compare the synthetic statistics with the\n   real ones.\n4. **Approve and publish.** A data owner or privacy officer signs off each new dataset\n   configuration; routine refreshes then run on a schedule or through an API into test, analytics\n   or sandbox environments.\n5. **Use and monitor.** Teams test, train or demo on the synthetic data, and results that matter\n   (a model going live, a performance benchmark) are confirmed on real data under proper controls.",[37,38,39,40],"speed","risk-reduction","compliance","employee-productivity",[42,43,44,45],"processing-time-reduction","cycle-time-days","users-served","productivity-gain",{"referenceOrg":47,"inputs":48,"formula":77,"currency":78,"period":79,"resultLabel":80,"caveat":81},"A bank with 30 delivery teams that request test data for their environments",[49,56,63,70],{"key":50,"label":51,"low":52,"high":53,"unit":54,"note":55},"requests","Test data requests per year",200,400,"requests per year","Editorial assumption for about 30 teams refreshing environments every few weeks. Replace with your own ticket volume.",{"key":57,"label":58,"low":59,"high":60,"unit":61,"note":62},"hoursPerRequest","Engineering hours to prepare one masked or hand built dataset",4,12,"hours per request","Editorial assumption covering extraction, masking, fixing broken references and checks. Patterson Dental reports 2.5 hours per dataset before automation.",{"key":64,"label":65,"low":66,"high":67,"unit":68,"note":69},"timeSaved","Share of preparation time removed",0.5,0.75,"fraction of hours","Capped at the benchmark on this page (Patterson Dental reports a 75% reduction in test data generation time).",{"key":71,"label":72,"low":73,"high":74,"unit":75,"note":76},"hourlyCost","Fully loaded cost of an engineer hour",60,100,"USD per hour","Editorial assumption. Replace with your own blended rate.","requests * hoursPerRequest * timeSaved * hourlyCost","USD","per year","Engineering time released from test data preparation","Counts only the preparation effort. It leaves out licence and compute cost, the risk reduction of removing personal data from lower environments, faster releases and fewer defects found late.",[],{"complexity":84,"complexityNote":85,"dataPrerequisites":86,"integrations":91},"medium","Generating a single table is easy. The work is in multi table data with referential integrity, business rules that must hold (a closed account has no new transactions), privacy measurement a privacy officer will accept, and pipelines that keep the synthetic data in step with schema changes.",[87,88,89,90],"Access to the source data inside a controlled environment, or a complete schema with business rules","A data classification that marks personal, special category and confidential fields","Agreed privacy, utility and fidelity thresholds per use (testing, model training, external sharing)","Examples of the rare cases and edge conditions tests must cover",[92,93,94,95],"Source databases and data warehouse for profiling","Target test, sandbox and analytics environments","CI pipelines and environment provisioning, so data refreshes run with deployments","Data catalogue for lineage and approval records",{"steps":97,"guardrails":116,"humanInTheLoop":122,"kpisToInstrument":123,"failureModes":129},[98,101,104,107,110,113],{"title":99,"detail":100},"Start where production copies hurt most","List the environments and teams that still receive production or lightly masked data, and pick one with a clear pain, such as a performance test that needs volume or a supplier that should never see real customers.",{"title":102,"detail":103},"Decide the privacy standard before generating anything","Agree with the privacy officer which checks a dataset must pass (no copied records, distance to closest real record, attribute inference tests) and who signs off. Treat the generator itself as processing of personal data, because it learns from it.",{"title":105,"detail":106},"Model the relationships, not just the columns","Map keys and business rules across tables and add them as constraints, so tests exercise real journeys. A customer without accounts or a claim without a policy produces false failures.",{"title":108,"detail":109},"Add the cases production lacks","Deliberately oversample fraud patterns, edge values, long names, rare products and multiple languages. This is where synthetic data beats a production copy.",{"title":111,"detail":112},"Automate refresh and measure use","Run generation from the pipeline on a schedule or per environment, and track requests, time to data and the defects found with synthetic data versus escaped defects.",{"title":114,"detail":115},"Keep real data for the final proof","For model training and validation, compare models trained on synthetic, mixed and real data before relying on synthetic data alone, and confirm go live decisions on real data under controls.",[117,118,119,120,121],"Generation runs inside the secured data environment; only the approved synthetic output leaves it","Every dataset passes automated privacy checks for copied records and reidentification risk before release","Stricter thresholds, or rule based generation without production data, for datasets shared outside the organization","Labels on every synthetic dataset so it is never mistaken for, or merged with, real data","Model decisions that affect customers are validated on real data, not on synthetic data alone","A data owner and the privacy officer approve each new dataset configuration and each external release, and review the privacy report. Test and data science leads confirm that the data is fit for purpose, and a person decides when a result on synthetic data is strong enough to act on.",[124,125,126,127,128],"Time from data request to usable test data","Share of test environments that hold no production personal data","Privacy test results per release (copied records, closest record distance)","Fidelity scores against the source statistics per dataset","Defects found in test versus defects that escape to production",[130,133,136,139],{"title":131,"detail":132},"Synthetic data that leaks real people","Overfitted generators can reproduce real records or rare outliers. Measure copies and closest records on every release and use differential privacy or stricter settings for sensitive data.",{"title":134,"detail":135},"Realistic columns, broken journeys","Distributions match but relationships and business rules do not, so tests fail for the wrong reasons or pass for the wrong reasons. Encode constraints and test the data itself.",{"title":137,"detail":138},"Models trained on synthetic data alone","Accuracy can drop sharply when real data is removed entirely. Keep a share of real data or validate on real data before deployment.",{"title":140,"detail":141},"A second shadow copy of production","Synthetic datasets proliferate without owners or labels. Register them in the catalogue with purpose, lineage and expiry.",{"euAiAct":143,"regulations":146,"guidance":152,"controls":164,"incidents":170},{"tier":144,"basis":145},"context-dependent","A generator of synthetic tabular test data is not listed in Annex III and does not interact with people, so it is minimal risk with only the AI literacy duty of Article 4. When the system generates synthetic text, images, audio or video, such as documents or conversation transcripts, Article 50(2) requires its provider to mark the output in a machine readable format as artificially generated. When synthetic data is used to train, validate or test a high risk system, such as credit scoring, it falls under that system's data governance duties in Article 10.",[147,148,149,150,151],"gdpr","uk-gdpr","eu-ai-act","hipaa","dora",[153,159],{"title":154,"issuer":155,"region":156,"url":157,"note":158},"What PETs are there? Synthetic data","UK Information Commissioner's Office","europe","https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/data-sharing/privacy-enhancing-technologies/what-pets-are-there/synthetic-data/","Guidance on synthetic data as a privacy enhancing technology. It notes that generating it from real data may involve processing personal information, that closer resemblance to real data raises the chance of revealing someone's information, and that biases carry through. The page says it is under review after the Data (Use and Access) Act.",{"title":160,"issuer":161,"region":156,"url":162,"note":163},"Using Synthetic Data in Financial Services","Financial Conduct Authority, Synthetic Data Expert Group","https://www.fca.org.uk/publication/corporate/report-using-synthetic-data-in-financial-services.pdf","March 2024 report with use cases on system testing, model validation and data sharing, and practical advice on evaluating privacy, utility and fidelity.",[165,166,167,168,169],"Data protection impact assessment for the generator and its training data","Documented privacy, utility and fidelity thresholds with sign off per dataset","Access control and logging on the environment where the generator sees real data","Catalogue entries with lineage, purpose and expiry for every synthetic dataset","Contract terms that forbid suppliers from attempting reidentification",[],{"howToBuild":172},"Blits.ai is not a tabular data synthesizer, but it is a practical way to generate synthetic\n**conversations and documents** and to orchestrate a dedicated generator. An **agentic workflow**\nwith **structured output** asks an agent to produce synthetic customers, transcripts, emails or\ncase files that follow a schema and a set of business rules, and **custom functions** call the\nAPI of the synthetic data engine the organization already uses for large tables. A **SQL\nknowledge base** lets an agent read aggregate statistics and schema information to steer\ngeneration, and **human in the loop confirmation** lets a data owner approve or reject each new\ndataset before the workflow publishes it.\n\n**PII masking** at the gateway keeps real personal data out of prompts, and the platform is\nmodel agnostic with **EU and UAE data residency**, so generation can run in the required region.\nSynthetic conversations can be imported as JSON test cases into **test suites** to evaluate chat\nand voice agents before launch, and **monitors** run scheduled checks against the live agents\nafterwards.",[174,177,180,183],{"question":175,"answer":176},"Is synthetic data still personal data under GDPR?","It can be. The FCA's Synthetic Data Expert Group notes that synthetic data tends to have a lower privacy risk than real data but cannot guarantee privacy, so a risk assessment per implementation is needed. Generation from real records is itself processing of personal data, and outputs should be tested for copied records and reidentification before release.",{"question":178,"answer":179},"Can synthetic data replace real data for training models?","Not always. In a proof of concept reported by the FCA's Synthetic Data Expert Group, a model trained on half synthetic and half real data scored 2.5% below the accuracy of the real data benchmark, while one trained on synthetic data only scored 32% below it. For software testing the bar is lower, because privacy and utility matter more than exact fidelity.",{"question":181,"answer":182},"How is synthetic data different from masked production data?","Masking keeps real records and replaces identifying fields, so relationships stay intact but people can sometimes still be identified from what remains. Synthetic data creates new records from learned patterns or rules. Many teams combine the two, as Kin Insurance did with subsetting, masking and differential privacy.",{"question":184,"answer":185},"How much faster does test data get?","The published cases report large gains in time to data. Patterson Dental reports test data generation falling from 2.5 hours to 35 minutes per dataset, and Merkur Versicherung reports time to data falling from one month to one day with a daily automated pipeline. Both are vendor case studies.",[187,188,189,190],"developer-coding-assistant","legacy-code-modernization","requirements-to-test-case-generation","model-risk-validation-copilot","2026-09-27","2026-09-26",[194],{"date":191,"note":195},"First published","synthetic-test-data-generation",[198,229,253,274,303,328,354],{"title":199,"useCases":200,"organization":201,"vendors":206,"summary":207,"stage":208,"year":209,"channels":210,"languages":211,"metrics":213,"outcomeDisclosed":221,"sources":222,"verification":224,"grade":226,"id":227,"organizationSlug":228},"Financial Conduct Authority: synthetic data in the Digital Sandbox and the Synthetic Data Expert Group",[196],{"name":202,"anonymized":203,"country":204,"region":156,"industry":205},"Financial Conduct Authority",false,"GB","government",[],"The UK Financial Conduct Authority has built synthetic datasets since a 2020 DataSprint, gave participants in two Digital Sandbox pilots access to synthetic data, opened a permanent Digital Sandbox in August 2023 and released an authorised push payment fraud synthetic dataset in September 2023, so firms can build and test solutions without real customer data. Its Synthetic Data Expert Group published a March 2024 report with use cases on system testing, model validation and data sharing, including the trade offs between privacy, utility and fidelity.","production",2023,[29],[212],"en",[214],{"kpi":44,"value":215,"unit":216,"qualifier":217,"period":218,"claimant":219,"quote":220,"sourceUrl":162},28,"count","exact","First Digital Sandbox pilot, organisations given access to synthetic data","organization","The first pilot, involving 28 organisations, underscored the value of synthetic data, emphasising the need for more referentially linked datasets and finer granularity.",true,[223],{"url":162,"title":160,"publisher":161},{"level":225,"checkedAt":192},"source-verified","B","financial-conduct-authority-synthetic-data-sandbox",null,{"title":230,"useCases":231,"organization":232,"vendors":236,"summary":237,"stage":208,"year":238,"channels":239,"languages":240,"metrics":241,"outcomeDisclosed":203,"sources":242,"verification":250,"grade":226,"id":251,"organizationSlug":252},"US Internal Revenue Service: Synthetic Data Engine for testing tax processing systems",[196],{"name":233,"anonymized":203,"country":234,"region":235,"industry":205},"Internal Revenue Service","US","north-america",[],"The IRS runs an AI based synthetic data generator that builds a large population of synthetic people, households and businesses, ages them over time and correlates them with the socioeconomic patterns of US taxpayers. It outputs synthetic individual and business tax returns for several tax years, plus the reference files that seed test systems, so tax processing systems can be tested, including simulated fraud cases, without exposing taxpayer information. Automated checks run on every schema version to catch anomalies in the generated returns. No outcome figures are published.",2022,[28],[212],[],[243,247],{"url":244,"title":245,"publisher":246},"https://github.com/ombegov/2025-Federal-Agency-AI-Use-Case-Inventory","2025 Federal Agency AI Use Case Inventory","Office of Management and Budget (GitHub)",{"url":248,"title":249,"publisher":246},"https://raw.githubusercontent.com/ombegov/2025-Federal-Agency-AI-Use-Case-Inventory/main/Data/2025_individually_reported_AI_use_cases.csv","2025 individually reported AI use cases (entry TREAS-85, Synthetic Data Engine)",{"level":225,"checkedAt":192},"irs-synthetic-data-engine","internal-revenue-service",{"title":254,"useCases":255,"organization":256,"vendors":258,"summary":261,"stage":208,"year":262,"channels":263,"languages":264,"metrics":265,"outcomeDisclosed":203,"sources":266,"verification":271,"grade":226,"id":272,"organizationSlug":273},"J.P. Morgan AI Research: synthetic financial datasets for AI research and development",[196],{"name":257,"anonymized":203,"country":234,"region":235,"industry":18},"JPMorgan Chase",[259],{"name":257,"role":260},"in-house","J.P. Morgan AI Research develops generators for realistic synthetic datasets in financial services and makes them available to researchers on request. The published sets cover anti money laundering customer traces, retail customer journeys, payments data for fraud detection, market order books, synthetic documents for layout recognition and simulated equity market data. Its documented method computes metrics on the real data, builds and optionally calibrates a generator (statistical or agent based simulation) and then compares the metrics of the synthetic and the real data. No business outcome figures are published.",2020,[28],[212],[],[267],{"url":268,"title":269,"publisher":270},"https://www.jpmorgan.com/technology/artificial-intelligence/initiatives/synthetic-data","Synthetic Data","JPMorganChase",{"level":225,"checkedAt":192},"jpmorgan-synthetic-data-research","jpmorgan-chase",{"title":275,"useCases":276,"organization":277,"vendors":280,"summary":284,"stage":208,"year":285,"channels":286,"languages":287,"metrics":288,"outcomeDisclosed":221,"sources":296,"verification":300,"grade":301,"id":302,"organizationSlug":228},"Boomi: synthetic data warehouse for employees building AI agents",[196],{"name":278,"anonymized":203,"country":234,"region":235,"industry":279},"Boomi","technology",[281],{"name":282,"role":283},"Tonic.ai","platform","Boomi, an integration platform company, gave employees in its citizen developer programme a synthetic copy of its Snowflake data warehouse, generated with Tonic Structural, so they can build and test AI agents and workflows without touching customer data. When a prototype is approved, the enterprise AI team points it at the production warehouse. Refreshes run automatically each weekend, and five agents were being rolled out when the story was published.",2026,[28],[212],[289],{"kpi":44,"value":290,"unit":216,"qualifier":291,"period":292,"claimant":293,"quote":294,"sourceUrl":295},2000,"approximately","Employees with access to the synthetic environment","vendor","With de-identified data from Tonic Structural, Boomi has opened its citizen developer program to approximately 2,000 people.","https://www.tonic.ai/case-study/boomi-synthetic-data-unblocks-ai-agent-innovation",[297],{"url":295,"title":298,"publisher":282,"date":299},"How Boomi unblocked 2,000 citizen developers to build AI agents with Tonic Structural","2026-07-07",{"level":225,"checkedAt":192},"C","boomi-synthetic-data-environment",{"title":304,"useCases":305,"organization":306,"vendors":308,"summary":310,"stage":208,"year":311,"channels":312,"languages":313,"metrics":314,"outcomeDisclosed":221,"sources":322,"verification":326,"grade":301,"id":327,"organizationSlug":228},"Patterson Dental: deidentified, production like test data for performance testing",[196],{"name":307,"anonymized":203,"country":234,"region":235,"industry":19},"Patterson Dental",[309],{"name":282,"role":283},"Patterson Dental, a division of Patterson Companies, uses Tonic Structural to generate deidentified, production like data for performance and functional testing of its dental practice platforms, so protected health information stays out of developer workflows. The vendor reports that test data preparation fell from 2.5 hours to 35 minutes per dataset and that performance testing grew from one practice to between 15 and 25 practices a day, with up to seven development teams using the data.",2025,[28],[212],[315],{"kpi":42,"value":316,"unit":317,"qualifier":217,"period":318,"baseline":319,"claimant":293,"quote":320,"sourceUrl":321},75,"percent","Test data generation time per dataset","2.5 hours per dataset, prepared manually from production","With Tonic Structural, the company achieved immediate and measurable improvements in their testing workflows, reducing test data generation time by 75% and cutting it down from 2.5 hours to just 35 minutes.","https://www.tonic.ai/case-study/patterson-test-data-better-software-for-thousands",[323],{"url":321,"title":324,"publisher":282,"date":325},"Patterson cuts test data time by 75% with Tonic.ai, delivering better software for thousands worldwide","2025-03-10",{"level":225,"checkedAt":192},"patterson-dental-deidentified-test-data",{"title":329,"useCases":330,"organization":331,"vendors":334,"summary":337,"stage":208,"year":209,"channels":338,"languages":339,"metrics":340,"outcomeDisclosed":221,"sources":348,"verification":352,"grade":301,"id":353,"organizationSlug":228},"Merkur Versicherung: daily synthetic copies of health insurance customer data",[196],{"name":332,"anonymized":203,"country":333,"region":156,"industry":20},"Merkur Versicherung AG","AT",[335],{"name":336,"role":283},"MOSTLY AI","The Merkur Innovation Lab, the innovation arm of the Austrian insurer Merkur Versicherung, runs an automated pipeline that extracts its active customer data (about 600,000 rows and 55 columns) from an Oracle database, has MOSTLY AI generate a synthetic version through a REST call and writes the result to a PostgreSQL database with Apache Airflow every day. The synthetic health data feeds internal analysis dashboards and is used to explore data sharing with third parties. The vendor reports that time to data fell from one month to one day.",[29,28],[],[341],{"kpi":43,"value":342,"unit":343,"qualifier":217,"period":344,"baseline":345,"claimant":293,"quote":346,"sourceUrl":347},1,"days","Time from data request to usable synthetic data","About one month before the automated pipeline","The end-to-end automated workflow has cut Merkur’s time-to-data from 1-month, to 1-day.","https://mostly.ai/blog/insurance-innovation-powered-by-synthetic-data",[349],{"url":347,"title":350,"publisher":336,"date":351},"Insurance innovation: 3 use cases powered by synthetic data in health insurance","2023-08-10",{"level":225,"checkedAt":192},"merkur-versicherung-synthetic-health-data",{"title":355,"useCases":356,"organization":357,"vendors":359,"summary":361,"stage":208,"year":238,"channels":362,"languages":363,"metrics":364,"outcomeDisclosed":203,"sources":365,"verification":370,"grade":301,"id":371,"organizationSlug":228},"Kin Insurance: masked and subsetted test databases for developers and QA",[196],{"name":358,"anonymized":203,"country":234,"region":235,"industry":20},"Kin Insurance",[360],{"name":282,"role":283},"Kin Insurance, a digital home insurer, sealed its production database off from development and now gives engineers and QA only subsetted, masked copies generated with Tonic, including differential privacy to protect people who stand out in the data. Developers use the subsets to fix bugs and build features, and QA uses the same data to check that releases behave as they did in the sandbox. The vendor reports faster data access and fewer security concerns but no quantified outcome beyond a database that can be pulled down in an hour or less.",[28],[212],[],[366],{"url":367,"title":368,"publisher":282,"date":369},"https://www.tonic.ai/case-study/kin-insurance-accelerates-growth-with-faster-more-secure-data-access-courtesy-of-tonic","Kin Insurance speeds growth with fast, secure data access from Tonic.ai","2022-07-05",{"level":225,"checkedAt":192},"kin-insurance-masked-test-data",[373,382,387],{"kpi":44,"label":374,"unit":216,"aggregate":203,"higherIsBetter":221,"n":375,"nUpTo":376,"median":377,"min":215,"max":290,"byClaimant":378,"vendorOnly":203,"points":379},"Users served",2,0,1014,{"organization":342,"vendor":342,"regulator":376,"independent":376},[380,381],{"evidenceId":302,"organization":278,"value":290,"qualifier":291,"claimant":293,"grade":301,"pooled":221},{"evidenceId":227,"organization":202,"value":215,"qualifier":217,"claimant":219,"grade":226,"pooled":221},{"kpi":43,"label":383,"unit":343,"aggregate":203,"higherIsBetter":203,"n":342,"nUpTo":376,"median":342,"min":342,"max":342,"byClaimant":384,"vendorOnly":221,"points":385},"Cycle time",{"organization":376,"vendor":342,"regulator":376,"independent":376},[386],{"evidenceId":353,"organization":332,"value":342,"qualifier":217,"claimant":293,"grade":301,"pooled":221},{"kpi":42,"label":388,"unit":317,"aggregate":221,"higherIsBetter":221,"n":342,"nUpTo":376,"median":316,"min":316,"max":316,"byClaimant":389,"vendorOnly":221,"points":390},"Cycle time reduction",{"organization":376,"vendor":342,"regulator":376,"independent":376},[391],{"evidenceId":327,"organization":307,"value":316,"qualifier":217,"claimant":293,"grade":301,"pooled":221},{"low":393,"high":394},24000,360000,[396,422,442,459],{"slug":187,"title":397,"shortTitle":398,"definition":399,"status":9,"industries":400,"functions":403,"patterns":404,"audience":406,"autonomy":407,"adoptionStage":408,"evidenceCount":409,"publicEvidenceCount":409,"organizations":410,"bestGrade":226,"headline":417,"lastVerified":191,"indexable":221},"AI coding assistant for software developers","Developer coding assistant","An AI assistant in the developer's IDE and code review flow that completes and generates code, explains unfamiliar modules, drafts unit tests and reviews pull requests for common defects, while generated code goes through the same review, testing and change controls as any other code.",[17,18,401,279,402],"capital-markets","professional-services",[22],[405],"code-generation","employee-facing","copilot","mainstream",6,[411,412,413,414,415,416],"Accenture","ANZ","Bank of America","Citi","CME Group","Meta",{"kpi":45,"label":418,"unit":317,"n":419,"nUpTo":376,"kind":420,"value":421,"qualifier":217,"claimant":228,"organization":228,"vendorReported":203},"Productivity gain",3,"median",20,{"slug":188,"title":423,"shortTitle":424,"definition":425,"status":9,"industries":426,"functions":428,"patterns":429,"audience":406,"autonomy":407,"adoptionStage":32,"evidenceCount":409,"publicEvidenceCount":432,"organizations":433,"bestGrade":226,"headline":439,"lastVerified":191,"indexable":221},"AI for legacy code modernization","Legacy code modernization","AI that reads legacy code such as COBOL, PL/I or old Java, explains what each program does, maps its data flows and dependencies, drafts the equivalent modern code or specification, and generates the regression tests needed to prove the new system behaves like the old one.",[17,18,401,427,279],"automotive",[22],[405,430,431],"summarization","agentic-workflow",5,[434,435,436,437,438],"Airbnb","Amazon","Google","Morgan Stanley","Toyota Motor Europe",{"kpi":42,"label":388,"unit":317,"n":342,"nUpTo":376,"kind":440,"value":441,"qualifier":291,"claimant":219,"organization":436,"vendorReported":203},"reported",50,{"slug":189,"title":443,"shortTitle":444,"definition":445,"status":9,"industries":446,"functions":447,"patterns":448,"audience":406,"autonomy":407,"adoptionStage":450,"evidenceCount":409,"publicEvidenceCount":432,"organizations":451,"bestGrade":226,"headline":457,"lastVerified":192,"indexable":221},"AI that turns requirements into user stories, acceptance criteria and test cases","Requirements to test cases","AI that reads product requirements, specifications or recorded sessions, checks them for gaps, ambiguity and contradictions, and drafts structured user stories, acceptance criteria and test cases (for example in Gherkin) that QA engineers review, with each item traced back to the requirement it covers.",[279,205,18,17],[22],[26,449],"document-processing","emerging",[452,453,454,455,456],"BrowserStack","Continental AG","LTIMindtree","National Aeronautics and Space Administration","U.S. Department of Veterans Affairs",{"kpi":42,"label":388,"unit":317,"n":342,"nUpTo":342,"kind":440,"value":458,"qualifier":217,"claimant":293,"organization":454,"vendorReported":221},67,{"slug":190,"title":460,"shortTitle":461,"definition":462,"status":9,"industries":463,"functions":465,"patterns":468,"audience":406,"autonomy":407,"adoptionStage":450,"segment":470,"evidenceCount":419,"publicEvidenceCount":419,"organizations":471,"bestGrade":226,"headline":228,"lastVerified":475,"indexable":221},"AI copilot for model risk validation and monitoring","Model risk validation","A copilot for independent model validation and review, whether run by a bank's validation function, an external tester or a supervisor, that checks model documentation against the model risk standard, generates and scores challenger tests (for generative AI, often with an LLM as a judge calibrated against human experts), watches production models for drift and drafts and consistency checks the validation report. An accountable validator owns every conclusion.",[18,20,401,464],"wealth-and-asset-management",[466,467],"risk-management","regulatory-compliance",[431,449,26,469],"anomaly-detection","second-line",[472,473,474],"European Central Bank (ECB Banking Supervision)","Standard Chartered","United Overseas Bank (UOB)","2026-09-28",{"indexable":221,"reasons":477},[],[479,485,490,498,505,510,516,522,530,537,543,549,556,563,569,574,581,586,591,597,603,609,615,620,625,632,639,644,649,656,662,668,674,679],{"id":149,"label":480,"issuer":481,"region":156,"url":482,"description":483,"useCases":484,"indexable":221},"EU AI Act","European Union","https://eur-lex.europa.eu/eli/reg/2024/1689/oj","Regulation (EU) 2024/1689: risk based rules for AI systems, with obligations for high risk systems listed in Annex III and transparency duties under Article 50.",197,{"id":147,"label":486,"issuer":481,"region":156,"url":487,"description":488,"useCases":489,"indexable":221},"GDPR","https://eur-lex.europa.eu/eli/reg/2016/679/oj","General Data Protection Regulation, including Article 22 on decisions based solely on automated processing.",180,{"id":491,"label":492,"issuer":493,"region":494,"url":495,"description":496,"useCases":497,"indexable":221},"iso-42001","ISO/IEC 42001","ISO and IEC","global","https://www.iso.org/standard/81230.html","The international management system standard for AI.",110,{"id":499,"label":500,"issuer":501,"region":235,"url":502,"description":503,"useCases":504,"indexable":221},"nist-ai-rmf","NIST AI Risk Management Framework","NIST","https://www.nist.gov/itl/ai-risk-management-framework","Voluntary US framework to map, measure, manage and govern AI risk, with a generative AI profile.",83,{"id":151,"label":506,"issuer":481,"region":156,"url":507,"description":508,"useCases":509,"indexable":221},"DORA","https://eur-lex.europa.eu/eli/reg/2022/2554/oj","Digital Operational Resilience Act for financial entities: ICT risk, incident reporting and third party risk, including AI providers.",66,{"id":148,"label":511,"issuer":512,"region":156,"url":513,"description":514,"useCases":515,"indexable":221},"UK GDPR","Information Commissioner's Office","https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/","The UK's version of the GDPR, including rules on solely automated decisions.",64,{"id":517,"label":518,"issuer":202,"region":156,"url":519,"description":520,"useCases":521,"indexable":221},"uk-consumer-duty","FCA Consumer Duty","https://www.fca.org.uk/firms/consumer-duty","UK rules that require firms to deliver good outcomes for retail customers, including through automated channels.",47,{"id":523,"label":524,"issuer":525,"region":526,"url":527,"description":528,"useCases":529,"indexable":221},"mas-ai-risk-management","MAS AI risk management guidelines","Monetary Authority of Singapore","asia-pacific","https://www.mas.gov.sg/news/media-releases/2025/mas-guidelines-for-artificial-intelligence-risk-management","Singapore's supervisory expectations for AI risk management at financial institutions, building on the FEAT principles.",36,{"id":531,"label":532,"issuer":533,"region":526,"url":534,"description":535,"useCases":536,"indexable":221},"apra-cps-230","APRA CPS 230","Australian Prudential Regulation Authority","https://www.apra.gov.au/operational-risk-management","Australian operational risk standard covering critical operations and material service providers.",25,{"id":538,"label":539,"issuer":540,"region":494,"url":541,"description":542,"useCases":421,"indexable":221},"pci-dss","PCI DSS","PCI Security Standards Council","https://www.pcisecuritystandards.org/","Security standard for any system that stores, processes or transmits cardholder data.",{"id":544,"label":545,"issuer":546,"region":235,"url":547,"description":548,"useCases":421,"indexable":221},"us-sr-11-7","SR 11-7 model risk management","Federal Reserve and OCC","https://www.federalreserve.gov/boarddocs/srletters/2011/sr1107.htm","US supervisory guidance on model risk management, applied by banks to AI and machine learning models.",{"id":550,"label":551,"issuer":552,"region":156,"url":553,"description":554,"useCases":555,"indexable":221},"uk-atrs","UK Algorithmic Transparency Recording Standard","UK Government","https://www.gov.uk/government/collections/algorithmic-transparency-recording-standard-hub","Mandatory transparency records for algorithmic tools used by UK central government.",16,{"id":557,"label":558,"issuer":559,"region":494,"url":560,"description":561,"useCases":562,"indexable":221},"fatf-recommendations","FATF Recommendations","Financial Action Task Force","https://www.fatf-gafi.org/en/publications/Fatfrecommendations/Fatf-recommendations.html","Global standards for anti money laundering and counter terrorist financing that national rules implement.",15,{"id":564,"label":565,"issuer":481,"region":156,"url":566,"description":567,"useCases":568,"indexable":221},"eu-amlr","EU Anti Money Laundering Regulation","https://eur-lex.europa.eu/eli/reg/2024/1624/oj","Regulation (EU) 2024/1624: the single EU rulebook for customer due diligence, beneficial ownership and suspicious transaction reporting.",14,{"id":570,"label":571,"issuer":481,"region":156,"url":572,"description":573,"useCases":568,"indexable":221},"nis2","NIS2 Directive","https://eur-lex.europa.eu/eli/dir/2022/2555/oj","Directive (EU) 2022/2555 on cybersecurity for essential and important entities, including telecom networks, energy and public administration.",{"id":575,"label":576,"issuer":577,"region":235,"url":578,"description":579,"useCases":580,"indexable":221},"us-bsa","Bank Secrecy Act","FinCEN","https://www.fincen.gov/resources/statutes-and-regulations/bank-secrecy-act","US anti money laundering law: customer due diligence, suspicious activity reports and record keeping.",13,{"id":582,"label":583,"issuer":481,"region":156,"url":584,"description":585,"useCases":60,"indexable":221},"eu-accessibility-act","European Accessibility Act","https://eur-lex.europa.eu/eli/dir/2019/882/oj","Directive (EU) 2019/882: accessibility requirements for banking services, ecommerce and other digital services, applicable since June 2025.",{"id":150,"label":587,"issuer":588,"region":235,"url":589,"description":590,"useCases":60,"indexable":221},"HIPAA","US Department of Health and Human Services","https://www.hhs.gov/hipaa/index.html","US rules for the privacy and security of protected health information.",{"id":592,"label":593,"issuer":594,"region":494,"url":595,"description":596,"useCases":60,"indexable":221},"telecom-consumer-rules","Telecom consumer protection rules","National telecom regulators","https://www.berec.europa.eu/","National rules on telecom contracts, switching, billing disputes and marketing consent.",{"id":598,"label":599,"issuer":481,"region":156,"url":600,"description":601,"useCases":602,"indexable":221},"eecc","European Electronic Communications Code","https://eur-lex.europa.eu/eli/dir/2018/1972/oj","Directive (EU) 2018/1972: consumer protection, contract, switching and security rules for telecom operators.",11,{"id":604,"label":605,"issuer":606,"region":235,"url":607,"description":608,"useCases":602,"indexable":221},"us-tcpa","Telephone Consumer Protection Act","Federal Communications Commission","https://www.fcc.gov/consumers/guides/stop-unwanted-robocalls-and-texts","US consent rules for automated and prerecorded calls and texts; the FCC has confirmed AI generated voices count as artificial voices.",{"id":610,"label":611,"issuer":525,"region":526,"url":612,"description":613,"useCases":614,"indexable":221},"mas-notice-626","MAS Notice 626","https://www.mas.gov.sg/regulation/notices/notice-626","Singapore's anti money laundering and counter terrorism financing requirements for banks.",10,{"id":616,"label":617,"issuer":481,"region":156,"url":618,"description":619,"useCases":614,"indexable":221},"mifid-ii","MiFID II","https://eur-lex.europa.eu/eli/dir/2014/65/oj","Directive 2014/65/EU on markets in financial instruments: suitability and appropriateness of advice, record keeping and product governance.",{"id":621,"label":622,"issuer":481,"region":156,"url":623,"description":624,"useCases":614,"indexable":221},"eu-psd2","PSD2","https://eur-lex.europa.eu/eli/dir/2015/2366/oj","Payment Services Directive 2: strong customer authentication, transaction risk analysis exemptions and open banking access.",{"id":626,"label":627,"issuer":628,"region":156,"url":629,"description":630,"useCases":631,"indexable":221},"eba-loan-origination","EBA Guidelines on loan origination and monitoring","European Banking Authority","https://www.eba.europa.eu/regulation-and-policy/credit-risk/guidelines-on-loan-origination-and-monitoring","Expectations for credit decisioning, including the use of automated models.",9,{"id":633,"label":634,"issuer":635,"region":235,"url":636,"description":637,"useCases":638,"indexable":221},"us-ecoa-reg-b","ECOA and Regulation B","Consumer Financial Protection Bureau","https://www.consumerfinance.gov/rules-policy/regulations/1002/9/","US fair lending rules, including specific reasons in adverse action notices, which also apply when credit decisions use AI models.",8,{"id":640,"label":641,"issuer":481,"region":156,"url":642,"description":643,"useCases":638,"indexable":221},"solvency-ii","Solvency II","https://eur-lex.europa.eu/eli/dir/2009/138/oj","Directive 2009/138/EC: risk based capital, governance and model requirements for insurers.",{"id":645,"label":646,"issuer":481,"region":156,"url":647,"description":648,"useCases":409,"indexable":221},"eu-idd","Insurance Distribution Directive","https://eur-lex.europa.eu/eli/dir/2016/97/oj","Directive (EU) 2016/97: conduct rules for selling insurance, including demands and needs testing and advice.",{"id":650,"label":651,"issuer":652,"region":653,"url":654,"description":655,"useCases":432,"indexable":221},"cbuae-ai-guidance","CBUAE guidance on AI and ML","Central Bank of the UAE","middle-east","https://www.centralbank.ae/","UAE central bank expectations for the enabling technologies, AI and machine learning used by licensed financial institutions.",{"id":657,"label":658,"issuer":659,"region":156,"url":660,"description":661,"useCases":59,"indexable":221},"pra-ss1-23","PRA SS1/23 model risk management","Prudential Regulation Authority","https://www.bankofengland.co.uk/prudential-regulation/publication/2023/may/model-risk-management-principles-for-banks-ss","UK model risk management principles for banks, covering AI and machine learning models.",{"id":663,"label":664,"issuer":665,"region":156,"url":666,"description":667,"useCases":59,"indexable":221},"uk-psr-app-reimbursement","UK APP scam reimbursement rules","Payment Systems Regulator","https://www.psr.org.uk/our-work/app-scams/","Mandatory reimbursement of authorised push payment scam victims by UK payment firms, which shifts scam losses onto banks.",{"id":669,"label":670,"issuer":671,"region":526,"url":672,"description":673,"useCases":419,"indexable":221},"au-scams-prevention-framework","Australian Scams Prevention Framework","Australian Treasury","https://treasury.gov.au/consultation/c2024-573813","Economy wide obligations for banks, telcos and digital platforms to prevent, detect, disrupt and respond to scams.",{"id":675,"label":676,"issuer":481,"region":156,"url":677,"description":678,"useCases":419,"indexable":221},"eu-mar","EU Market Abuse Regulation","https://eur-lex.europa.eu/eli/reg/2014/596/oj","Regulation (EU) 596/2014: insider dealing and market manipulation, including the duty to detect and report suspicious orders and transactions.",{"id":680,"label":681,"issuer":682,"region":235,"url":683,"description":684,"useCases":419,"indexable":221},"us-fcra","Fair Credit Reporting Act","Federal Trade Commission","https://www.ftc.gov/legal-library/browse/statutes/fair-credit-reporting-act","US rules on consumer reports, their accuracy and permissible use, relevant to credit scoring and screening.",1790598301881]