Who it is for

One engine, many regulated sectors.

Regulated firms face the same question in every sector: who may use AI on which material, under which controls, and who answers for the result. What changes from sector to sector is the material, the rules and the workflows. GAIA Brain is designed to keep the controls common and adapt the rest to each sector.

The model

A shared core, a layer per sector.

GAIA-CORE is the engine: identity and clearance, protected egress, model routing and the tamper-evident record, the part that stays constant whatever the sector. On top of it sits a sector layer: the approved sources, roles, obligations and workflows a particular regulated domain needs. Finance and health do not share a rulebook; they can share the controls that make AI-assisted work reviewable.

That is why one core can serve more than one sector without becoming a vague horizontal tool. The depth lives in the sector layer, while reusable access, egress and evidence controls live in the core and still require deployment-specific validation.

Where we start

Built first for AIFMs and asset managers.

The first vertical under design is regulated investment management: firms supervised under regimes such as AIFMD and MiFID II, where one prompt can carry client positions, holdings or market-sensitive information. The obligations are precise and the workflow burden is visible. It is the right place to test whether the architecture creates measurable operating value.

We are starting here because it is the domain we know from the inside, in a regulated EU market.

Then, the adjacent sectors

The same problem, different sensitive data.

Each of these is a regulated profession where confidentiality is not a preference but a duty, and where staff are already pasting privileged material into public AI tools. The sector layer changes; the core does not.

Law

Legal privilege and client confidentiality, for lawyers who need AI to be useful without putting that privilege at risk.

Audit

Client financials and independence rules, where what leaves the firm has to be accounted for.

Insurance

Health and financial data of policyholders, much of it special-category under the GDPR.

Health

Patient data, the strictest special-category regime there is, where a careless export is both a breach and a harm.

A distinct horizon

EU institutions and bodies.

Beyond the commercial sectors sits a different kind of user. EU institutions, bodies, offices and agencies process personal data under their own regulation, Regulation (EU) 2018/1725, the counterpart to the GDPR written for the Union’s own administration. They face the same question every regulated firm faces: how to use frontier AI without exporting data they are bound to protect.

We treat this as a horizon, deliberately separate from the near-term commercial verticals above. The architecture applies cleanly. The path to serving it is a longer one, but the roadmap is set.

Read more