Anthony Spadaro is the founder and CEO of Vantomic Inc., an agency building agentic AI software for nuclear power and energy operations.
Many of my projects involve building agentic AI systems for companies operating in heavily regulated industries, like nuclear power. In early 2026, I also took a course on deploying agentic AI for executives to better understand whether there’s a gap between the teachings and my own experience.
One lesson has become clear: in a regulated industry, the value of an AI agent isn’t based primarily on what the model can do, but on how the company sets the boundary lines. I’ll discuss what that looks like in practice, and the first thing I’d do if I were charged with introducing AI agents in an environment where a failure is a reportable incident instead of a bad quarterly earnings report.
Think of the agent as a boundary, not a capability.
Every single agentic system I’ve built boils down to five considerations:
1. What can the agent observe?
2. What actions can it perform?
3. How does it plan?
4. What can it remember?
5. How is safety enforced around it?
Vendors often showcase only the first three. Safety teams and regulators are interested in all five, and in my experience, the last two are typically underdeveloped.
For nuclear, this approach is liberating. No one will let an agent control a safety system, nor should they. But an agent that can only read facility documents, check them against regulatory obligations, generate a compliance document and send it to a licensed individual is quite different from the Hollywood depiction. The issue changes from “Can we trust AI?” to “What precisely can this system observe and do, and can we demonstrate that?”
Nuclear companies already understand how to do that. They’ve been drawing boundaries around equipment and personnel for years. A good first step is to draft these five considerations on one sheet before any programming happens, with the “prohibited” list exceeding the “permitted” list.
Don’t expect the model to handle risk management.
Large language models (LLMs) are stochastic. You can’t unit test them like regular code, and they can be influenced. Consequently, the safety rules can’t be embedded in the model. They need to exist outside the model, including hard-coded limits the model can’t circumvent, an additional review stage prior to anything reaching a human or a downstream process, actions designed to be undoable and a validated procedure for a human takeover when the agent approaches its limit of authority.
Regulated businesses will recognize this as risk management applied to software. The novel element is deciding those boundaries in advance and translating them into explicit rules. I view human oversight not as a simple toggle, but as a series of thresholds: below one threshold, the agent can act on its own; above another, it must escalate for review; beyond a third, a human takes over.
These thresholds turn an organization’s risk tolerance into operational rules the system can enforce. Defining them in advance also forces executive teams to make explicit decisions about where they are comfortable delegating authority and where they are not.
Anticipate organizational impediments, not technical ones.
When my team works with a big regulated client, the technical integration is seldom the bottleneck. The bottleneck is getting the IT, security, ops, legal and management folks into one room and negotiating what the agent can do and who’s responsible when it does it. I’ve seen that take weeks while the implementation took days. This is remediable, since you can design for readiness.
There are two things that have been key. One is to assign every agent a responsible manager, and ensure that manager is a domain expert instead of an engineer. The person who’s qualified to evaluate whether an agent’s compliance decisions are still sound needs to be someone who understands what a sound compliance decision looks like. And second, bring in the users in advance. The friction around using AI in serious settings is rarely fear of technology. It’s a very valid fear of receiving a system no one understands and being asked to vouch for it.
View governance as your advantage.
An organization that can demonstrate to a regulator what the agents can see, what actions they can take, how the outputs are validated and how oversight is performed continuously is building something that rivals will struggle to replicate. In all industries where confidence is the price of admission, it’s the transparent and verifiable systems that will get rolled out. All others are likely to stay in the sandbox.
It’s early. Implementing autonomous AI in regulated sectors will be a slow and careful process, and rightly so. But the organizations that are defining the parameters now and cultivating the managers who will run the systems inside them are the ones likely to be prepared when the throttle can actually be cranked.
Disclosure: The author’s firm creates and distributes agentic AI platforms, including for use within regulated businesses.
Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?
