Use cases

Twelve workflows four industries

Finance, healthcare, defence, manufacturing. Pick the one that pays back.

Financial services Healthcare & life sciences Government & defence Manufacturing & supply chain
Where AIA pays back

Find your business case

Value type on the Y-axis, speed on the X. Click a tile.

USE-CASE FIT MATRIX VALUE TYPE (Y) × SPEED OF ADOPTION (X) VALUE TYPE SPEED OF ADOPTION QUICK WINS LONG TERM NEW REVENUE COST, RISK & COMPLIANCE P3 · PRODUCT PASSPORT F1 · AI TRADING H1 · DRUG DISCOVERY H3 · REAL-WORLD EVIDENCE G2 · ALLIED COORDINATION F2 · M&A DILIGENCE H2 · TRIAL SITES G1 · INTEL FUSION P1 · LkSG / CSDDD P2 · SCOPE 3 EMISSIONS F3 · CROSS-BANK AML G3 · DEFENSE SUPPLY CHAIN
Financial
Healthcare
Government & defence
Manufacturing & supply chain

Quick wins ship solo; long-term plays need consortium partners.

01 · Financial services

Banks, asset managers, trading desks

AIA puts the analysis inside the bank: strategies stay private and settlement runs on MiFID II-grade stablecoin rails.

MiCA MiFID II AMLA · 6AMLD Basel III FATF Travel Rule DORA
FINANCIAL SERVICES · ONE ENCLAVE, THREE OUTPUTS BANK ENCLAVE · AIA · DATA STAYS IN KNOWLEDGE GRAPH SPECIALIST AGENTS ZKP settles ZKP REGULATOR ZK proofs · L1 anchored STABLECOIN RAIL MiCA · atomic settlement BANK CONSORTIUM ZK pattern · network graph three outputs cross the boundary · zero raw data leaves
Data stays in the bank; only three things cross the perimeter: a regulator proof, settlement, a pattern signature.
Use case · F1

AI trading on stablecoins

Agents run the strategy and settle on regulated stablecoin; risk and compliance become public proofs.

01 INGESTStrategy, risk limits, whitelists, and venue books load into the trader's local graph.
02 ORCHESTRATEExecution, risk, compliance, and settlement agents run the strategy in the enclave. Order and position never leave.
03 REASONEach trade clears a cryptographic gate — risk, sanctions, best execution — proven publicly, details kept private.
04 ATTESTSettlement is atomic on the stablecoin rail; the regulator verifies the proof.
Without AIAStrategies leak through order flow and settlement is T+2 with counterparty risk.
With AIAStrategy stays with the trader, the regulator sees only proofs, and settlement is atomic.
Confidential institutional trading with a verifiable audit trail.
DeploymentHybrid · in-network UrgencyMiCA live · MiFID II Time to pilot12–18 weeks Partner anchorstablecoin issuer · planned
Use case · F2

M&A due diligence

Specialist agents work every diligence stream in parallel while book data stays in the bank.

01 INGESTTarget filings, disclosures, the counterparty graph, and prior same-sector diligences load into the deal graph.
02 ORCHESTRATESpecialist agents run in parallel — Research, Forecasting, Market Modeling, Compliance, and more from AIA's agent fleet.
03 REASONThe graph surfaces hidden ownership chains, related-party flows, and unnamed risks; prior deals add their findings.
04 ATTESTConclusions cite their source and agent. The Knowledge Graph keeps the pattern for the next target.
Without AIAAdvisor-run diligence, billed per deal, with book data sent out under NDA.
With AIAThe work runs inside the firm; book data stays and every deal speeds up the next.
The diligence playbook stays in-house — and compounds with every deal.
DeploymentHybrid · in-network UrgencyPer-deal · ad-hoc Time to pilot4–8 weeks Partner anchorcorp dev · pipeline
Use case · F3

Cross-bank AML intelligence

Member banks share laundering patterns as cryptographic signatures; customer data never crosses.

01 INGESTEach bank's payments, customer graph, sanctions lists, and prior cases stay in its local Knowledge Graph.
02 ORCHESTRATEA detected pattern — mule network, structuring, layering, sanctions evasion — posts to the network graph as a proof.
03 REASONOther members check incoming payments against the network signatures; false positives drop.
04 ATTESTPattern signatures are signed by their source bank; trace-back is possible if needed. Customer identity never crosses.
Without AIAEach bank's AML model learns only from its own data and false positives dominate the casework.
With AIAMembers see the network signal while customer secrecy holds through cryptography.
Material false-positive reduction plus a new consortium revenue line.
DeploymentHybrid per bank UrgencyAMLA · 6AMLD · Travel Rule Time to pilot14–20 weeks · per consortium Partner anchorbank consortium · pipeline
Evidence pack · financial services
  • Stablecoin settlement integration spec — interface to MiCA-compliant USDC, EURC, and equivalent issuers. Atomic settlement with the cryptographic gate.
  • M&A diligence agent set — ten specialist agent configurations, scoring schemas, and the citation-chain contract.
  • Federated AML consortium charter — membership terms, cryptographic-pattern schema, trace-back protocol.
  • Data processing agreement — pre-drafted for German law and EU SCCs.
  • Sub-processor list — zero net-new sub-processors for in-network deployments.
  • Bank reference architecture — Terraform and Helm modules, under NDA.

Documents on signed request via the contact form.

02 · Healthcare & life sciences

Pharma, hospital networks, life-science consortia

Medicine's most valuable data can't legally leave the hospital, so AIA sends the query to the HIPAA-bound data instead.

HIPAA BAA-ready FDA 21 CFR Part 11 EU EHDS GDPR ICH GCP
HEALTHCARE · FEDERATION ACROSS PHARMA AND HOSPITALS ⊗ NO MOLECULES OR PHI CROSS A PERIMETER SHARED LANDSCAPE aggregates only PHARMA A · R&D molecules · assays PHARMA B · R&D molecules · assays HOSPITAL NET · EU EHR · cohort HOSPITAL NET · US EHR · cohort ZKP · target ZKP · target ZKP · cohort ZKP · cohort pharma IP stays · patient records stay · shared landscape grows
Each enclave keeps its own IP or PHI; the shared output is a cryptographic aggregate.
Use case · H1

Federated drug discovery

Pharma rivals share negative results as cryptographic signatures; molecules and IP stay private.

01 INGESTEach pharma loads internal R&D — assays, biomarker correlations, SAR data, failed leads — into its enclave.
02 ORCHESTRATEDiscovery agents test hypotheses locally. The pattern signature posts to the shared landscape; the molecule doesn't.
03 REASONThe shared landscape surfaces industry-wide dead-ends, correlations, and hotspots — answers built from competitor signal no one sees directly.
04 ATTESTContributions are signed; attribution and licensing rights stay intact.
Without AIAEach pharma re-discovers the same dead-ends and consortia collapse the moment IP risk appears.
With AIAMembers see what no single pharma can; IP stays put.
Federated R&D where IP integrity is cryptographic, not contractual.
DeploymentHybrid per pharma UrgencyR&D productivity crisis Time to pilot24–36 weeks · per consortium Partner anchorpharma R&D consortium · planned
Use case · H2

Clinical trial site selection

Sponsors find sites straight from the protocol; patient records never leave the hospital.

01 INGESTThe sponsor writes inclusion/exclusion criteria; each hospital has its population indexed locally.
02 ORCHESTRATEEach hospital matches locally; a coordinator ranks sites on candidate count, operational fit, and prior performance.
03 REASONThe next study in the same area runs faster, and the hospital network owns the relationship.
04 ATTESTThe sponsor gets a ranked list with a proof of each count. No PHI crosses a boundary.
Without AIACRO back-and-forth, gated by the CRO's site network.
With AIAThe hospital network is the counterparty. The CRO is optional.
Site selection straight from the protocol. Sponsor and sites deal directly.
DeploymentHybrid per site UrgencyPer-trial · ad-hoc Time to pilot6–10 weeks Partner anchorsponsor + hospital network · pipeline
Use case · H3

Real-world evidence federation

Real-world evidence is assembled across hospital networks; no patient record crosses a boundary.

01 INGESTNetworks index EHRs locally; the sponsor defines cohort, comparator arm, and endpoints.
02 ORCHESTRATEEach network runs exposure, outcome, and confounding analysis on local data; results return as attested aggregates.
03 REASONThe sponsor assembles the RWE package from federated proofs — demographics, outcomes, comparator, sensitivity all auditable.
04 ATTESTThe FDA/EMA submission has provenance for every data point; later studies reuse the same rails.
Without AIAEach hospital negotiated separately, study by study.
With AIAMulti-network from day one, with cryptographically attested data quality.
Faster label expansion. Hospital networks earn licensing royalties on every subsequent study.
DeploymentHybrid per network UrgencyFDA RWE · EU EHDS Time to pilot12–20 weeks · per network Partner anchorpharma + EHDS data holder · planned
Evidence pack · healthcare & life sciences
  • HIPAA BAA — template available; execution per engagement on the Managed tier. In-network deployments don't need one.
  • Pharma R&D federation charter — consortium membership terms, cryptographic target schema, IP attribution protocol.
  • Hospital network onboarding kit — local data dictionary, aggregate-export contract, IRB-ready boilerplate per site.
  • RWE submission template — FDA RWE framework alignment, EU EHDS data-holder agreement, statistical proof schemas.
  • 21 CFR Part 11 record spec — electronic record and signature schema with a validation harness.
  • Noise-budget spec — per-query privacy parameters and the audit log they generate.

Documents on signed request via the contact form.

03 · Government & defence

Ministries, intelligence agencies, defence primes

AIA runs on air-gapped sovereign hardware, where one post-quantum agent-to-agent protocol handles intelligence fusion, allied coordination, and supplier attestation.

NSM-10 BSI TR-02102 CMMC 2.0 DFARS · ITAR CHIPS Act BSI C5
GOVERNMENT & DEFENCE · ONE PROTOCOL, THREE WORKLOADS AGENCY A · AIR-GAPPED · AIA ⊗ NO OUTBOUND CONNECTIVITY CORPUS A sigint · humint · osint GRAPH · A AGENT FLEET sources & methods stay inside enclave TYPED QUERIES ↔ ZKP ANSWERS A2A BRIDGE ML-KEM-1024 ML-DSA-87 "is there overlap on X?" AGENCY B / PRIME · ENCLAVED · AIA ⊗ NO OUTBOUND CONNECTIVITY AGENT FLEET GRAPH · B CORPUS B sigint · humint · BOM sources, methods & supplier IP stay inside enclave two enclaves · one typed conversation · zero raw data
One agent-to-agent bridge carries all three workloads: typed queries cross the perimeter, raw data does not.
Use case · G1

Intelligence fusion

Agents fuse SIGINT, HUMINT, and OSINT inside the enclave; clearance boundaries hold by construction.

01 INGESTSIGINT, HUMINT, OSINT, and partner feeds load into the air-gapped graph at their classification level; agents extract entities, events, and relations.
02 ORCHESTRATEAgents are partitioned by clearance. The protocol blocks cross-domain queries, not analyst discipline.
03 REASONThe fusion engine correlates findings across sources and scores confidence; provenance stays with every assertion.
04 ATTESTThe product publishes inside the classified network. Any cleared reviewer can replay the chain; the analyst signs the judgment on top.
Without AIAOne pair of eyes per source, with manual correlation and leakage riding on discipline.
With AIAAgents correlate and the analyst signs; cross-domain leakage becomes a protocol error.
Multi-source fusion at agency scale. Compartmentation enforced cryptographically. Post-quantum throughout.
DeploymentSovereign · air-gapped UrgencyNSM-10 · TR-02102 Time to pilot16–24 weeks Partner anchorministry · pipeline
Use case · G2 · A2A

Allied agency coordination

Two agencies coordinate via the post-quantum protocol: typed queries cross, raw intelligence does not.

01 INGESTEach agency's agents authenticate with their own decentralised identity — no shared accounts.
02 ORCHESTRATEThe bridge carries typed questions — "overlap on entity X?", "target Y in your watch set?" — encrypted with ML-KEM-1024, signed with ML-DSA-87.
03 REASONEach side queries its own collection in-enclave; only the typed answer crosses.
04 ATTESTAnswers travel as cryptographic proofs — yes or no, without revealing what's underneath. Both enclaves keep the audit log.
Without AIALiaison is slow and lossy, so the safer call is often not to share.
With AIAAgent-to-agent at machine speed, with bounded question types and each side keeping its collection.
Post-quantum agent-to-agent coordination. Bilateral. Extensible to multilateral.
DeploymentSovereign · paired UrgencyPQC mandated · NSM-10 Time to pilot16–28 weeks · per pair Partner anchorbilateral coalition · planned
Use case · G3

Defense supply-chain integrity

CMMC posture is verified down to Tier-N suppliers, who reveal no internals.

01 INGESTEach subcontractor runs AIA in its security boundary; asset graphs, CMMC controls, country-of-origin, and component lots stay local.
02 ORCHESTRATECompliance agents attest CMMC level, ITAR posture, and country-of-origin via cryptographic proofs. Provenance agents sign every component lot.
03 REASONThe prime sees a live verification graph: every Tier-N supplier compliant or not, every component traceable to origin — with no internal documents revealed.
04 ATTESTCounterfeit or sanctioned components fail the proof at integration. CMMC audit packages assemble from the chain; delivery BOMs anchor on L1.
Without AIACMMC is self-attested at every tier and counterfeit chips reach defense systems.
With AIACompliance is cryptographic at every tier and the prime sees through to the foundry.
Cryptographically verifiable defense supply chain. Compliance is checked, not declared.
DeploymentSovereign per supplier UrgencyCMMC 2.0 · DFARS · CHIPS Time to pilot16–28 weeks · per prime Partner anchordefense prime · planned
Evidence pack · government & defence
  • NSM-10 / BSI TR-02102 mapping — which algorithms, what key sizes, when to migrate.
  • Air-gapped reference architecture — Sovereign-tier topology, self-hosted, no outbound traffic.
  • Clearance-aware policy spec — the type schema and enforcement model behind the cross-domain bridge.
  • A2A bilateral playbook — bilateral deployment procedure under reciprocal agreement, including key-rotation and audit-log exchange.
  • Defense supply-chain attestation kit — Tier-N CMMC schema, country-of-origin proof circuit, BOM provenance anchor format.
  • Export-control posture — ITAR / EAR classification of the primitives and source.

Cleared engagements receive additional materials under signed NDA or sponsorship.

04 · Manufacturing & supply chain

OEMs, industrial groups, luxury and life-science brands

CSDDD demands supply-chain visibility no manufacturer can audit, so each supplier runs an AIA node in its own perimeter.

LkSG EU CSDDD CSRD EU DPP · ESPR DSCSA Conflict Minerals · 3TG
MANUFACTURING · ATTESTATIONS UP THE CHAIN ⊗ NO COMMERCIAL DATA CROSSES A TIER TIER-N · RAW mines · foundries · farms TIER-N · WORKFORCE hours · wages · safety TIER-N · ENERGY kWh · fuel · process GHG ZKP· provenance ZKP· CSDDD · CSRD TIER-3 · TIER-2 aggregates · re-attests ZKP· aggregate payments TIER-1 subassembly · BOM signed ZKP· component lot payments OEM · BRAND CSDDD · CSRD report DPP per unit Tier-N visibility without supplier books each tier keeps its books · cryptographic proofs travel up · brand sees the chain
The chain carries cryptographic proofs of compliance, origin, and emissions; each supplier keeps its books.
Use case · P1

Supply chain due diligence

Tier-N suppliers attest from inside their own perimeter; the OEM proves CSDDD compliance.

01 INGESTEach supplier runs AIA; workforce records, environmental controls, sub-supplier registers, and process data stay local.
02 ORCHESTRATECompliance agents map the data to LkSG and CSDDD duties: forced and child labor, wages, association, discharge, conflict minerals.
03 REASONAttestations flow up: Tier-N → Tier-3 → Tier-2 → Tier-1 → OEM. Aggregation is cryptographic at every step; supplier internals stay private.
04 ATTESTThe OEM's annual LkSG and CSDDD filing is signed by the chain of attestations; the auditor verifies it directly.
Without AIAA pyramid of audit fees per OEM, while Tier-3 and below stay invisible.
With AIACryptographic attestations replace the audit pyramid, giving the OEM provable Tier-N visibility.
Scalable CSDDD compliance with Tier-N visibility.
DeploymentHybrid per supplier UrgencyLkSG live · CSDDD by 2027 Time to pilot16–24 weeks · per supply chain Partner anchorindustrial OEM · pipeline
Use case · P2

Scope 3 carbon emissions

Suppliers attest their own emissions, so Scope 3 aggregates from primary data, not industry averages.

01 INGESTEach supplier loads energy, fuel, process emissions, and product-level allocation into its local graph; volumes stay private.
02 ORCHESTRATEGHG agents apply the GHG Protocol categories, allocating emissions to products and customers by the supplier's chosen method.
03 REASONSupplier emissions attest upward at product-volume granularity. Aggregate Scope 3 is built from primary data, not industry averages; cost data stays private.
04 ATTESTThe Big-4 assurance engagement verifies the proofs. The CSRD disclosure has provenance for every emission factor.
Without AIAScope 3 uses industry averages auditors can't verify, raising greenwashing exposure every cycle.
With AIAPrimary supplier data without exposing cost, with both assurance levels working.
Scope 3 disclosure built on primary supplier data.
DeploymentHybrid per supplier UrgencyCSRD FY2024 · reasonable assurance 2028 Time to pilot12–20 weeks Partner anchorindustrial OEM + Big-4 · planned
Use case · P3

Digital Product Passport

The full unit history is provable from foundry to retail; counterfeits fail at integration.

01 INGESTThe whole chain — extraction, smelting, fabrication, assembly, packaging, shipping, customs, retail — runs AIA, signing each handoff.
02 ORCHESTRATEProvenance agents check that each step's input matches the prior step's output. Substitution breaks the signature chain.
03 REASONThe DPP for each unit assembles from the chain: materials, processing, carbon, refurbishability, and ownership history.
04 ATTESTA QR code verifies the full history against the L1 anchor. Buyer, regulator, and recall coordinator check the same chain.
Without AIACounterfeits bleed luxury brands and recalls take months.
With AIACounterfeits fail at integration and recalls trace the full chain, meeting the EU DPP rules.
Digital Product Passport with cryptographic chain of custody.
DeploymentHybrid per node UrgencyEU DPP 2026–2030 · ESPR Time to pilot12–18 weeks · per product line Partner anchorluxury / pharma / semis brand · pipeline
Evidence pack · manufacturing & supply chain
  • LkSG & CSDDD obligation graph — the schema mapping supplier records to statutory duties, with the auditor-verification path.
  • CSRD Scope 3 proof circuit — GHG Protocol category templates, allocation logic, and the assurance-engagement bridge for Big-4 verification.
  • Digital Product Passport reference — schema, QR-anchor format, EU DPP / ESPR alignment, conflict-minerals (3TG) coverage.
  • Supplier-attestation onboarding kit — what a Tier-3 supplier installs, how its perimeter is configured, and the proof-only egress contract.
  • BOM provenance specification — per-lot signature chain, anchor cadence, recall-trace procedure.
  • Industrial reference architecture — Sovereign and Hybrid topology for a supplier network, with Helm and Terraform modules under NDA.

Documents on signed request via the contact form.

Why now

Behind each workflow, a clock

The cards above exist because one of these is counting down.

Live · Jan 2025
DORA
EU operational resilience for financial firms: IT vendor risk, incident reporting, evidence chain.
Up to 2% of global revenue · daily fine
2 Dec 2027
EU AI Act · Annex III high-risk obligations
Art. 12 logging, human oversight, conformity assessment — re-timed by the Digital Omnibus.
Up to €35M or 7% · penalty regime of the Act
2025 → 2027
NIS2 national rollout
EU directive into national law: supply-chain provenance, 24-hour incident reporting, board-level sign-off.
€10M or 2% · personal liability on the board
By 2030
NSM-10 · mid-migration
US federal critical systems migrate to post-quantum crypto; BSI TR-02102 mirrors the timeline in Europe.
Federal contracting · NATO interoperability
By 2035
Full post-quantum
All US federal systems on post-quantum. RSA and ECDSA become audit findings; traffic recorded today is in range of decryption.
Latent risk on today's traffic

Penalties are statutory maxima. How AIA addresses each framework: trust · compliance.

The first call

Three questions
we answer on the first call

A working session, not a sales meeting.

01 · The data

What can't leave?

Which datasets must stay where — picking Managed, Hybrid, or Sovereign.

02 · The work

What's the workflow?

Maps to one of the twelve, or a new one we sketch together.

03 · The proof

What does success look like?

The measurable outcome, and the evidence your auditor needs.

Bring your hardest workflow

If none of the twelve match your workflow, bring yours.

Five design-partner slots a year. Regulated industries only.
Book a call Write to us

Thirty minutes. Three questions. One-page outcome.