Sectors

The same AI risks, different consequences.

We focus on sectors where an AI failure has real consequences. The method stays the same; what we prioritise depends on what the system can reach.

Where we focus

Six sectors, one method.

For each sector: where AI typically shows up, and the risks we look at first. Risk codes refer to the OWASP Top 10 for LLM Applications 2026.

Government

Where AI shows up

Citizen-facing assistants, document and case processing, internal knowledge search, and decision support.

What we look at first

  • Personal data surfacing in answers (LLM02)
  • Assistants acting beyond their remit (LLM03)
  • Confident wrong answers in decisions that matter (LLM07)

Some government and critical-infrastructure testing in the UAE requires specific accreditation. We will tell you at scoping whether an engagement is one we can take on.

Financial services

Where AI shows up

Customer service agents, analyst copilots over internal research, document review, and fraud and compliance workflows.

What we look at first

  • Leakage across clients or roles in retrieval (LLM09)
  • Prompt injection through uploaded documents and emails (LLM01)
  • Model output reaching downstream systems unchecked (LLM10)

Energy & infrastructure

Where AI shows up

Maintenance and engineering copilots, operational knowledge search, and reporting automation near operational technology.

What we look at first

  • Agents with tool access near operational systems (LLM03)
  • Poisoned manuals or procedures in retrieval data (LLM05)
  • Third-party models and plugins in the supply chain (LLM04)

Healthcare

Where AI shows up

Clinical documentation assistants, patient communication, triage support, and research search over sensitive records.

What we look at first

  • Sensitive health information in outputs (LLM02)
  • Plausible but wrong clinical content (LLM07)
  • Hidden instructions extracted from system prompts (LLM08)

Technology

Where AI shows up

AI features inside products, coding agents, support automation, and AI vendors preparing for enterprise customers.

What we look at first

  • Excessive agency in product-embedded agents (LLM03)
  • Cost and denial-of-service abuse (LLM06)
  • Independent evidence for enterprise buyers before delivery

Other critical industries

Where AI shows up

Logistics, aviation, telecoms and other sectors where an AI failure has operational, safety or regulatory consequences.

What we look at first

  • The full OWASP LLM Top 10, scoped to what the system can reach
  • Application, API, identity and infrastructure around the model
  • Clear limits and residual risk, stated in writing

Next step

Working in one of these sectors?

Tell us what your AI system does and what it can reach. We will tell you which risks matter most, and whether we can help.

Talk to us

A scoping conversation first. Nothing starts until scope and limits are agreed in writing.